Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 93 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 418 respecto a la semana anterior
146 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.33% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key, such as a PKCS#8 EncryptedPrivateKeyInfo or "ENCRYPTED PRIVATE KEY" PEM file, to… | |
| Pendiente de análisis | Alta (8.2) | 0.24% | — | Bouncycastle BC CsharpAI | 2/10/2026 | 2/10/2026 | Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by… | |
| Pendiente de análisis | Alta (8.2) | 0.22% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to obtain certificates with chosen subjectAltName URIs from such a CA, to bypass permitted or excluded… | |
| Pendiente de análisis | Alta (7.1) | 0.19% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote, unauthenticated attacker who can supply a crafted… | |
| Pendiente de análisis | Alta (8.2) | 0.31% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who holds a captured CMS EnvelopedData message, and who can submit many modified messages to an application that decrypts… | |
| Pendiente de análisis | Alta (7.1) | 0.33% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in… | |
| Pendiente de análisis | Alta (8.7) | 0.17% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to have a forged X.509 attribute certificate accepted as valid, and so… | |
| Pendiente de análisis | Alta (7.1) | 0.21% | — | Legion OF THE Bouncy Castle INC BC CsharpAI | 2/10/2026 | 2/10/2026 | Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never… | |
| Pendiente de análisis | Alta (8.7) | 0.26% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL,… | |
| Pendiente de análisis | Alta (8.7) | 0.41% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory… | |
| Pendiente de análisis | Alta (8.2) | 0.24% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS… | |
| Pendiente de análisis | Alta (8.2) | 0.29% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to obtain decryptions of ciphertexts of their choosing via forged messages sent to an application that lets the output buffer of… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service via a crafted ASN.1 encoding of deeply nested constructed elements (for example SEQUENCE inside SEQUENCE, in… | |
| Pendiente de análisis | Crítica (9.1) | 0.40% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a CMP message or CRMF certificate request whose… | |
| Pendiente de análisis | Alta (8.2) | 0.47% | — | Legion OF THE Bouncy Castle INC BC CsharpAI | 2/10/2026 | 2/10/2026 | Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack,… | |
| Pendiente de análisis | Alta (8.7) | 0.37% | — | Bouncycastle BC CsharpAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated DTLS peer to cause a denial of service through memory exhaustion via crafted handshake message fragments,… | |
| Pendiente de análisis | Alta (8.2) | 0.17% | — | Legion OF THE Bouncy Castle BC CsharpAI | 2/10/2026 | 2/10/2026 | Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has observed one encrypted message with known plaintext to forge shorter… | |
| Pendiente de análisis | Alta (8.7) | 0.25% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags, via messages encrypted without… | |
| Pendiente de análisis | Alta (8.2) | 0.23% | — | Bouncycastle Bc-csharpAI | 2/10/2026 | 2/10/2026 | Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without detection via an AlgorithmIdentifier whose CCMParameters declare an authentication… | |
| Pendiente de análisis | Alta (8.7) | 0.81% | — | Sharp Multifunction PrinterAIToshibatec Multifunction PrinterAI | 1/10/2026 | 2/10/2026 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as… | |
| Aplazada | Alta (8.7) | 0.22% | — | Code16 SharpAI | 24/9/2026 | 29/9/2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve… | |
| Aplazada | Alta (7.3) | 0.21% | — | Code16 SharpAI | 24/9/2026 | 30/9/2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is… | |
| Aplazada | Media (5.3) | 0.40% | — | CefsharpAI | 18/8/2026 | 9/9/2026 | CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsWith(rootFolder, StringComparison.OrdinalIgnoreCase) to decide whether a decoded… |