Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.56% | — | Heinekingmedia Stashcat | 17/6/2020 | 17/6/2026 | An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext, enabling an attacker (by copying or having access to the local storage database file) to login to… | |
| Modificada | Alta (7.2) | 1.7% | — | Heinekingmedia Stashcat | 18/5/2020 | 17/6/2026 | An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string, which allows attackers to obtain sensitive information by reading web-server logs. | |
| Modificada | Media (6.5) | 0.50% | — | Stashcat Heinekingmedia | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. It uses RSA to exchange a secret for symmetric encryption of messages. However, the private RSA key is not only stored on the client but transmitted to the backend, too. Moreover, the… | |
| Modificada | Alta (7.5) | 1.1% | — | Stashcat Heinekingmedia | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The logout mechanism does not check for authorization. Therefore, an attacker only needs to know the device ID. This causes a denial of service. This might be interpreted as a… | |
| Modificada | Media (6.5) | 0.82% | — | Stashcat Heinekingmedia | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them. | |
| Modificada | Alta (7.5) | 0.68% | — | Stashcat Heinekingmedia | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. To encrypt messages, AES in CBC mode is used with a pseudo-random secret. This secret and the IV are generated with math.random() in previous versions and with… | |
| Modificada | Alta (7.5) | 0.51% | — | Heinekingmedia Stashcat | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; therefore the attacker could issue a certificate for the backend and the application would not notice it. | |
| Modificada | Media (5.9) | 0.55% | — | Stashcat Heinekingmedia | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. For authentication, the user password is hashed directly with SHA-512 without a salt or another key-derivation mechanism to enable a secure secret for authentication. Moreover, only… | |
| Modificada | Alta (8.1) | 0.40% | — | Stashcat Heinekingmedia | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure confidentiality. In the whole protocol, no integrity or authenticity checks are done. Therefore man-in-the-middle attackers can conduct… | |
| Modificada | Crítica (9.8) | 1.1% | — | Stashcat Heinekingmedia | 1/8/2017 | 17/6/2026 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore can read the content out, for example the private key of the user. |