Jahlives
66 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-81680
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted…
2026-08-27
CVE-2026-81681
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encr…
2026-08-27
CVE-2026-81682
HIGH 8.6
Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI th…
2026-08-27
CVE-2026-81683
HIGH 8.6
Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in c…
2026-08-27
CVE-2026-81684
MEDIUM 6.9
Openssl Encrypt — In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography p…
2026-08-27
CVE-2026-81685
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing att…
2026-08-27
CVE-2026-81686
MEDIUM 6.9
Openssl Encrypt — openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Proper…
2026-08-27
CVE-2026-81687
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration coun…
2026-08-27
CVE-2026-81688
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file hea…
2026-08-27
CVE-2026-81689
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA…
2026-08-27
CVE-2026-81690
HIGH 8.7
Openssl Encrypt — openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file a…
2026-08-27
CVE-2026-81691
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions,…
2026-08-27
CVE-2026-81692
HIGH 8.7
Openssl Encrypt — openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total…
2026-08-27
CVE-2026-81693
HIGH 8.7
Openssl Encrypt — openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing rang…
2026-08-27
CVE-2026-81694
CRITICAL 9.3
Openssl Encrypt — openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (o…
2026-08-27
CVE-2026-81695
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr durin…
2026-08-27
CVE-2026-81696
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by…
2026-08-27
CVE-2026-81697
HIGH 8.7
Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file reso…
2026-08-27
CVE-2026-81698
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstruc…
2026-08-27
CVE-2026-81699
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files…
2026-08-27
CVE-2026-81700
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_deta…
2026-08-27
CVE-2026-81701
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned p…
2026-08-27
CVE-2026-81702
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identit…
2026-08-27
CVE-2026-81703
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys…
2026-08-27
CVE-2026-81704
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.E…
2026-08-27
CVE-2026-81705
HIGH 8.7
Openssl Encrypt — openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is s…
2026-08-27
CVE-2026-81706
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in Iden…
2026-08-27
CVE-2026-81707
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attack…
2026-08-27
CVE-2026-81714
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_tr…
2026-08-27
CVE-2026-81715
HIGH 8.7
Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passe…
2026-08-27
CVE-2026-81716
HIGH 8.7
Openssl Encrypt — openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._i…
2026-08-27
CVE-2026-81717
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive f…
2026-08-27
CVE-2026-81718
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations …
2026-08-27
CVE-2026-81719
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin sig…
2026-08-27
CVE-2026-81720
MEDIUM 6.9
Openssl Encrypt — openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks,…
2026-08-27
CVE-2026-81721
HIGH 8.7
Openssl Encrypt — openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore hea…
2026-08-27
CVE-2026-74870
HIGH 8.7
Openssl Encrypt — openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-tes…
2026-08-17
CVE-2026-74871
MEDIUM 6.9
Openssl Encrypt — openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where t…
2026-08-17
CVE-2026-74872
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash …
2026-08-17
CVE-2026-74873
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listi…
2026-08-17
CVE-2026-74874
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel se…
2026-08-17
CVE-2026-74875
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not …
2026-08-17
CVE-2026-74876
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key …
2026-08-17
CVE-2026-74877
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key…
2026-08-17
CVE-2026-74878
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is no…
2026-08-17
CVE-2026-74879
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint t…
2026-08-17
CVE-2026-74880
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry…
2026-08-17
CVE-2026-74881
HIGH 7.1
Openssl Encrypt — openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials …
2026-08-17
CVE-2026-74882
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 191…
2026-08-17
CVE-2026-74883
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to…● PoC
2026-08-17
CVE-2026-74884
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where…
2026-08-17
CVE-2026-74885
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module count…
2026-08-17
CVE-2026-74886
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuar…
2026-08-17
CVE-2026-74887
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at lin…
2026-08-17
CVE-2026-74888
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 …
2026-08-17
CVE-2026-74889
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization fun…
2026-08-17
CVE-2026-74890
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that di…
2026-08-17
CVE-2026-74891
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuratio…
2026-08-17
CVE-2026-74892
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry serve…
2026-08-17
CVE-2026-74893
HIGH 8.7
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass val…
2026-08-17
CVE-2026-74894
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function …
2026-08-17
CVE-2026-74895
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode…
2026-08-17
CVE-2026-74896
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AS…● PoC
2026-08-17
CVE-2026-74899
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that ex…● PoC
2026-08-17
CVE-2026-74900
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failu…
2026-08-17
CVE-2026-74901
CRITICAL 9.3
Openssl Encrypt — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM d…
2026-08-17