Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4) | 0.13% | — | Notaryproject Notation-goAI | 13/1/2025 | 17/6/2026 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp… | |
| Analizada | Baja (3.3) | 0.19% | — | Notaryproject Notation-go | 13/1/2025 | 17/6/2026 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check feature. After retrieving the CRL, notation-go attempts to update the… | |
| Analizada | Alta (7.4) | 0.22% | — | Codenotary Immudb | 31/7/2024 | 17/6/2026 | mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack. | |
| Modificada | Media (6.8) | 0.29% | — | Notaryproject Notation-go | 19/1/2024 | 17/6/2026 | The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts. An external actor with control of a compromised container registry can provide outdated versions of OCI artifacts, such… | |
| Modificada | Alta (8.8) | 0.35% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above. Users unable to upgrade… | |
| Modificada | Media (6.5) | 0.48% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation verify command on the same machine. The problem has been fixed in… | |
| Modificada | Media (5.7) | 0.51% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation inspect command on the same machine. The problem has been fixed… | |
| Modificada | Alta (7.5) | 0.44% | — | Notaryproject Notation-go | 20/2/2023 | 17/6/2026 | notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The application will be killed, and thus availability is impacted. The problem has… | |
| Modificada | Media (5.3) | 0.41% | — | Codenotary Immudb | 23/11/2022 | 17/6/2026 | immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server… | |
| Modificada | Media (5.9) | 0.28% | — | Codenotary Immudb | 22/11/2022 | 17/6/2026 | immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. SDK does not validate this uuid and can accept any value… | |
| Modificada | Crítica (9.8) | 2.3% | — | Notary Docker Image | 8/12/2020 | 17/6/2026 | The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 1.3% | — | Docker Notary | 31/3/2018 | 17/6/2026 | In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file. | |
| Modificada | Alta (7.5) | 1.0% | — | Docker Notary | 31/3/2018 | 17/6/2026 | In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve… |