Vulnerabilities

Summary — last 7 days

New vulnerabilities2,811▲ 64 vs. last week
Critical / high1,484▲ 296 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)68▼ 448 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.3)1.4%—Evmos EthermintKavaCrypto CronosEvmos8/5/20226/17/2026
Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the internal database storage. However, due to a bug in the `DeleteAccount`function, all contracts that used the identical bytecode (i.e shared…
ModifiedHigh (7.5)1.3%—Crypto CronosCrypto EthermintCrypto Evmos12/21/20216/17/2026
Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. This problem has been patched in Cronos v0.6.5. There are no tested workarounds.…
ModifiedHigh (7.5)1.5%—Chainsafe Ethermint2/8/20216/17/2026
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage changes caused by a failed transaction are improperly reserved in memory. Although the bad storage cache data will be…
ModifiedHigh (7.5)1.3%—Chainsafe Ethermint2/8/20216/17/2026
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts.
ModifiedHigh (7.5)1.3%—Chainsafe Ethermint2/8/20216/17/2026
Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch,…
ModifiedHigh (7.5)1.1%—Chainsafe Ethermint2/8/20216/17/2026
Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application.