Vulnerabilities

Summary — last 7 days

New vulnerabilities2,500▼ 420 vs. last week
Critical / high1,284▲ 11 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 465 vs. last week
–

13 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.31%—Zcashfoundation ZebraAIZfnd ZebradAI10/2/202610/2/2026
ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort…
DeferredMedium (6.9)0.39%—Zcash Foundation ZebraAI10/2/202610/2/2026
The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can…
DeferredMedium (6.9)0.30%—Zcash Foundation ZebraAI10/2/202610/2/2026
ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing…
DeferredCritical (9.3)0.51%—ZebraAIElectriccoin ZcashdAI8/18/20269/9/2026
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcodes. In zebra-script/src/lib.rs, p2sh_input_sigop_count used the pure-Rust…
DeferredCritical (9.3)0.32%—ZebradAIHalo2 GadgetsAIZcash PrimitivesAIOrchardproject OrchardAI+17/17/20267/17/2026
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying…
DeferredLow (3.5)0.25%—Electriccoin ZcashdAI4/5/20267/24/2026
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
ModifiedMedium (6.1)0.38%—Woocommerce Jazzcash Gateway5/9/20236/17/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in JC Development Team WooCommerce JazzCash Gateway Plugin plugin <= 2.0 versions.
ModifiedMedium (5.3)1.0%—Electriccoin Zcashd2/5/20216/17/2026
In Electric Coin Company Zcashd before 2.1.1-1, the time offset between messages could be leveraged to obtain sensitive information about the relationship between a suspected victim's address and an IP address, aka a timing side channel.
ModifiedHigh (7.5)1.0%—Electriccoin Zcashd2/5/20216/17/2026
Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid chain could be incorrectly rejected because timestamp requirements on block headers were not properly enforced.
ModifiedMedium (5.3)1.6%—Z.cash Zcash9/28/20196/17/2026
Zcashd in Zcash before 2.0.7-3 allows discovery of the IP address of a full node that owns a shielded address, related to mishandling of exceptions during deserialization of note plaintexts. This affects anyone who has disclosed their zaddr to a third party.
ModifiedHigh (7.5)2.2%—Z.cash Zcash5/1/20196/17/2026
Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.
ModifiedHigh (7.5)2.2%—Z.cash Zcash3/27/20196/17/2026
Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, during evaluation of polynomials related to a to-be-proven statement, produced certain bypass elements. Availability of these elements allowed a cheating prover to bypass a consistency check, and…
ModifiedMedium (5.3)1.1%—Ewbf Cuda Zcash Miner10/15/20176/17/2026
The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or…