Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.16% | — | GNU PsppAI | 9/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The… | |
| Aplazada | Baja (1.9) | 0.16% | — | GNU PsppAI | 9/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to… | |
| Analizada | Media (5.6) | 0.25% | — | GNU Glibc | 5/6/2025 | 17/6/2026 | The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and… | |
| Analizada | Media (5.6) | 0.31% | — | GNU Glibc | 5/6/2025 | 17/6/2026 | The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and… | |
| Aplazada | Media (4.4) | 0.29% | — | GNU CoreutilsAI | 27/5/2025 | 28/9/2026 | A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data. | |
| Modificada | Media (4.8) | 0.29% | — | GNU Binutils | 27/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the… | |
| Modificada | Media (4.8) | 0.28% | — | GNU Binutils | 27/5/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (7.3) | 0.21% | — | GNU ScreenAI | 26/5/2025 | 17/6/2026 | Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be… | |
| Aplazada | Media (5.1) | 0.22% | — | GNU ScreenAI | 26/5/2025 | 17/6/2026 | The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system. | |
| Aplazada | Media (5.7) | 0.17% | — | GNU ScreenAI | 26/5/2025 | 17/6/2026 | Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root. | |
| Aplazada | Baja (2) | 0.22% | — | GNU ScreenAI | 26/5/2025 | 17/6/2026 | A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0. | |
| Analizada | Media (4.8) | 0.29% | — | GNU Pspp | 20/5/2025 | 17/6/2026 | A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit… | |
| Analizada | Media (5.5) | 0.16% | — | GNU Pspp | 16/5/2025 | 17/6/2026 | libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read. | |
| Modificada | Alta (7.8) | 0.59% | 💥 PoC | GNU Glibc | 16/5/2025 | 17/6/2026 | Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo). | |
| Analizada | Crítica (9.1) | 0.35% | — | GNU Pspp | 10/5/2025 | 17/6/2026 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document. | |
| Analizada | Crítica (9.8) | 0.30% | — | GNU Pspp | 10/5/2025 | 17/6/2026 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c. | |
| Analizada | Crítica (9.8) | 0.30% | — | GNU Pspp | 10/5/2025 | 17/6/2026 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c. | |
| Aplazada | Media (5.9) | 0.35% | — | GNU GrubAILinux LuksAI | 9/5/2025 | 1/9/2026 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can corrupt the underlying filesystem… | |
| Modificada | Media (5.5) | 0.21% | — | Gnuplot | 7/5/2025 | 26/6/2026 | gnuplot is affected by a heap buffer overflow at function utf8_copy_one. | |
| Analizada | Media (5.5) | 0.18% | — | GNU Pspp | 3/5/2025 | 17/6/2026 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code. | |
| Modificada | Media (5.3) | 0.45% | 💥 PoC | GNU Mailman | 20/4/2025 | 17/6/2026 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used. | |
| Modificada | Alta (8.1) | 0.59% | 💥 PoC | GNU Mailman | 20/4/2025 | 17/6/2026 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel… | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | GNU Mailman | 20/4/2025 | 17/6/2026 | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this,… | |
| Aplazada | Crítica (9.8) | 0.50% | — | SIR GnucommerceAI | 15/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4. | |
| Aplazada | Media (6.2) | 0.20% | — | GnuplotAI | 7/4/2025 | 17/6/2026 | A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment. |