← Browse

Jahlives

66 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-81680 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted… 2026-08-27 CVE-2026-81681 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encr… 2026-08-27 CVE-2026-81682 HIGH 8.6 Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI th… 2026-08-27 CVE-2026-81683 HIGH 8.6 Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in c… 2026-08-27 CVE-2026-81684 MEDIUM 6.9 Openssl Encrypt — In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography p… 2026-08-27 CVE-2026-81685 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing att… 2026-08-27 CVE-2026-81686 MEDIUM 6.9 Openssl Encrypt — openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Proper… 2026-08-27 CVE-2026-81687 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration coun… 2026-08-27 CVE-2026-81688 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file hea… 2026-08-27 CVE-2026-81689 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA… 2026-08-27 CVE-2026-81690 HIGH 8.7 Openssl Encrypt — openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file a… 2026-08-27 CVE-2026-81691 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions,… 2026-08-27 CVE-2026-81692 HIGH 8.7 Openssl Encrypt — openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total… 2026-08-27 CVE-2026-81693 HIGH 8.7 Openssl Encrypt — openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing rang… 2026-08-27 CVE-2026-81694 CRITICAL 9.3 Openssl Encrypt — openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (o… 2026-08-27 CVE-2026-81695 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr durin… 2026-08-27 CVE-2026-81696 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by… 2026-08-27 CVE-2026-81697 HIGH 8.7 Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file reso… 2026-08-27 CVE-2026-81698 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstruc… 2026-08-27 CVE-2026-81699 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files… 2026-08-27 CVE-2026-81700 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_deta… 2026-08-27 CVE-2026-81701 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned p… 2026-08-27 CVE-2026-81702 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identit… 2026-08-27 CVE-2026-81703 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys… 2026-08-27 CVE-2026-81704 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.E… 2026-08-27 CVE-2026-81705 HIGH 8.7 Openssl Encrypt — openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is s… 2026-08-27 CVE-2026-81706 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in Iden… 2026-08-27 CVE-2026-81707 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attack… 2026-08-27 CVE-2026-81714 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_tr… 2026-08-27 CVE-2026-81715 HIGH 8.7 Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passe… 2026-08-27 CVE-2026-81716 HIGH 8.7 Openssl Encrypt — openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._i… 2026-08-27 CVE-2026-81717 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive f… 2026-08-27 CVE-2026-81718 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations … 2026-08-27 CVE-2026-81719 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin sig… 2026-08-27 CVE-2026-81720 MEDIUM 6.9 Openssl Encrypt — openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks,… 2026-08-27 CVE-2026-81721 HIGH 8.7 Openssl Encrypt — openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore hea… 2026-08-27 CVE-2026-74870 HIGH 8.7 Openssl Encrypt — openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-tes… 2026-08-17 CVE-2026-74871 MEDIUM 6.9 Openssl Encrypt — openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where t… 2026-08-17 CVE-2026-74872 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash … 2026-08-17 CVE-2026-74873 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listi… 2026-08-17 CVE-2026-74874 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel se… 2026-08-17 CVE-2026-74875 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not … 2026-08-17 CVE-2026-74876 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key … 2026-08-17 CVE-2026-74877 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key… 2026-08-17 CVE-2026-74878 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is no… 2026-08-17 CVE-2026-74879 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint t… 2026-08-17 CVE-2026-74880 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry… 2026-08-17 CVE-2026-74881 HIGH 7.1 Openssl Encrypt — openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials … 2026-08-17 CVE-2026-74882 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 191… 2026-08-17 CVE-2026-74883 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to…● PoC 2026-08-17 CVE-2026-74884 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where… 2026-08-17 CVE-2026-74885 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module count… 2026-08-17 CVE-2026-74886 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuar… 2026-08-17 CVE-2026-74887 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at lin… 2026-08-17 CVE-2026-74888 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 … 2026-08-17 CVE-2026-74889 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization fun… 2026-08-17 CVE-2026-74890 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that di… 2026-08-17 CVE-2026-74891 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuratio… 2026-08-17 CVE-2026-74892 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry serve… 2026-08-17 CVE-2026-74893 HIGH 8.7 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass val… 2026-08-17 CVE-2026-74894 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function … 2026-08-17 CVE-2026-74895 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode… 2026-08-17 CVE-2026-74896 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AS…● PoC 2026-08-17 CVE-2026-74899 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that ex…● PoC 2026-08-17 CVE-2026-74900 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failu… 2026-08-17 CVE-2026-74901 CRITICAL 9.3 Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM d… 2026-08-17