Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Analizada | Alta (8.8) | 70% | ⚠ Explotación activa | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraWebkitgtk+8 | 28/7/2022 | 4/8/2026 | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 0.82% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction. | |
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Averta Shortcodes AND Extra Features FOR Phlox Theme | 11/7/2022 | 17/6/2026 | The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Oceanwp Ocean Extra | 20/6/2022 | 17/6/2026 | The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.8) | 1.4% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 16/6/2022 | 17/6/2026 | A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior. | |
| Modificada | Alta (7.8) | 1.4% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 16/6/2022 | 17/6/2026 | A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior. | |
| Modificada | Alta (7.5) | 1.1% | — | Markdown-link-extractor Project Markdown-link-extractor | 2/6/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function | |
| Modificada | Media (6.1) | 0.79% | — | Donate Extra Project Donate Extra | 23/5/2022 | 17/6/2026 | The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting | |
| Modificada | Alta (7.5) | 2.8% | — | FreerdpFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 26/4/2022 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is… | |
| Modificada | Alta (7.5) | 4.2% | — | Golang GOFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 20/4/2022 | 17/6/2026 | The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input. | |
| Modificada | Crítica (9.8) | 4.9% | — | GITFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 19/4/2022 | 17/6/2026 | The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command… | |
| Modificada | Alta (8.8) | 0.93% | — | MoodleFedoraproject FedoraFedoraproject Extra Packages FOR Enterprise Linux | 25/3/2022 | 17/6/2026 | An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default. | |
| Modificada | Alta (7.5) | 3.9% | — | Golang SSHFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Advanced Cluster Management FOR Kubernetes | 18/3/2022 | 17/6/2026 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | |
| Modificada | Alta (7.5) | 2.5% | 💥 PoC | KeepassFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 10/3/2022 | 17/6/2026 | A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs. | |
| Modificada | Media (6.5) | 4.7% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+16 | 10/3/2022 | 17/6/2026 | There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to… | |
| Modificada | Alta (7.8) | 1.2% | — | BlenderFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 24/2/2022 | 17/6/2026 | A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution. | |
| Analizada | Media (5.5) | 0.73% | — | Metadata-extractor Project Metadata-extractor | 24/2/2022 | 17/6/2026 | When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library. | |
| Analizada | Media (5.5) | 0.78% | — | Metadata-extractor Project Metadata-extractor | 24/2/2022 | 17/6/2026 | metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library. | |
| Modificada | Alta (7.5) | 6.0% | — | Prometheus Client GolangFedoraproject FedoraFedoraproject Extra Packages FOR Enterprise LinuxRDO Project RDO | 15/2/2022 | 17/6/2026 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory… | |
| Modificada | Media (6.1) | 1.3% | — | Phoronix-media Phoronix Test SuiteFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 14/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2. | |
| Modificada | Media (4.3) | 0.90% | — | Futuriowp Futurio Extra | 14/2/2022 | 17/6/2026 | The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address. | |
| Modificada | Baja (2.7) | 0.85% | — | Futuriowp Futurio Extra | 14/2/2022 | 17/6/2026 | The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a malicious link. |