Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 2.1% | — | Apache Commons ConfigurationFedoraproject FedoraNetapp Ontap ToolsNetapp Snapcenter | 21/3/2024 | 17/6/2026 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | |
| Modificada | Media (4.3) | 0.72% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (6.5) | 0.85% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.72% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.65% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.88% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.82% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 21% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.4% | — | Latchset JoseFedoraproject Fedora | 20/3/2024 | 17/6/2026 | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | |
| Modificada | Media (6.5) | 0.27% | — | Fedoraproject FedoraXEN | 20/3/2024 | 17/6/2026 | Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to protect against Return Oriented Programming attacks. When enabled, traditional stacks holding both data and return addresses are accompanied by… | |
| Analizada | Media (4.1) | 0.26% | — | XENFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out of Xen. | |
| Analizada | Media (5.3) | 0.80% | — | XENFedoraproject Fedora | 20/3/2024 | 17/6/2026 | PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend the number of outstanding requests. Such phantom functions need an IOMMU context setup, but failure to… | |
| Analizada | Alta (7.5) | 1.1% | — | Libdwarf Project LibdwarfRedhat Enterprise LinuxFedoraproject Fedora | 18/3/2024 | 17/6/2026 | A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results. | |
| Modificada | Alta (7.5) | 23% | 💥 PoC | Apache TomcatDebian LinuxFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects… | |
| Modificada | Media (6.3) | 2.3% | — | Apache TomcatDebian LinuxFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85,… | |
| Analizada | Alta (8.8) | 0.71% | — | Google ChromeFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (6.5) | 0.67% | — | Broadcom TcpreplayFedoraproject Fedora | 12/3/2024 | 17/6/2026 | Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command. | |
| Modificada | Alta (7.5) | 2.0% | 💥 PoC | Libexpat Project LibexpatFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+10 | 10/3/2024 | 17/6/2026 | libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). | |
| Analizada | Alta (7.4) | 0.74% | — | Kozea WeasyprintFedoraproject Fedora | 9/3/2024 | 17/6/2026 | WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2. | |
| Analizada | Media (4.3) | 2.0% | — | Go-jose Project Go-joseFedoraproject Fedora | 9/3/2024 | 17/6/2026 | Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data… | |
| Analizada | Media (5.9) | 2.1% | — | Jose Project JoseFedoraproject Fedora | 9/3/2024 | 17/6/2026 | jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces,… | |
| Modificada | Media (6.5) | 1.5% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Modificada | Media (6.5) | 1.3% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+5 | 8/3/2024 | 17/6/2026 | An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user. | |
| Modificada | Media (6.5) | 1.5% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Modificada | Media (6.5) | 1.3% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin. |