Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1280 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.3) | 0.64% | — | GNU Binutils | 10/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is… | |
| Modificada | Baja (2.3) | 0.67% | — | GNU Binutils | 10/2/2025 | 17/6/2026 | A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.5) | 0.40% | — | Indeed UtilAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Alta (7.5) | 0.44% | — | Cli-utilAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Utils-extendAI | 5/2/2025 | 17/6/2026 | The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence. | |
| Aplazada | Alta (7.5) | 0.40% | — | Xe-utilsAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Alta (7.5) | 0.55% | — | UtileAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Analizada | Baja (3.4) | 0.69% | — | Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+12 | 5/2/2025 | 17/6/2026 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
| Analizada | Media (6.3) | 0.75% | — | GNU Binutils | 29/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack… | |
| Aplazada | Alta (8.6) | 0.19% | — | Adobe Flash Programming UtilityAI | 24/1/2025 | 17/6/2026 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
| Aplazada | Media (5.5) | 0.25% | — | GNU BinutilsAI | 21/1/2025 | 17/6/2026 | https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function. | |
| Aplazada | Media (6.4) | 0.28% | — | Utilities FOR MTGAI | 18/1/2025 | 17/6/2026 | The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.38% | — | GIT Utilities Project GIT Utilities | 9/1/2025 | 17/6/2026 | Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*. | |
| Aplazada | Baja (3.6) | 0.43% | 💥 PoC | Shadow-utils ShadowAI | 26/12/2024 | 17/6/2026 | shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap… | |
| Analizada | Media (6.7) | 0.17% | — | Dell Dock Hd22q Firmware Update UtilityDell Dock Wd19 Firmware Update UtilityDell Dock Wd22tb4 Firmware Update Utility | 11/12/2024 | 17/6/2026 | Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Modificada | Baja (3.4) | 1.3% | — | Haxx CurlNetapp OntapNetapp Ontap Select Deploy Administration UtilityNetapp H610c Firmware+7 | 11/12/2024 | 17/6/2026 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either… | |
| Aplazada | Media (6.5) | 0.16% | — | HPE Nonstop Disk UtilAI | 22/11/2024 | 17/6/2026 | A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series. | |
| Analizada | Media (4.4) | 0.21% | — | Dell Intel Management Engine Firmware Update Utility | 22/11/2024 | 17/6/2026 | Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this… | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Utility FOR Overclocking Control | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Media (5.3) | 0.30% | — | Iowacomputergurus Aspnetcore.utilities.cloudstorage | 30/10/2024 | 17/6/2026 | ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired. Users not… | |
| Analizada | Baja (3.3) | 0.14% | — | Hashicorp Vagrant Vmware Utility | 29/10/2024 | 17/6/2026 | The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23 | |
| Analizada | Media (5.9) | 1.0% | 💥 PoC | Netapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+8 | 27/10/2024 | 17/6/2026 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. | |
| Aplazada | Media (6.3) | 0.76% | — | XZ UtilsAI | 2/10/2024 | 17/6/2026 | XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerability. If a command line contains Unicode characters (for example, filenames) that… | |
| Analizada | Media (6.5) | 0.73% | — | Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 11/9/2024 | 17/6/2026 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for… | |
| Analizada | Alta (7.5) | 52% | 💥 Exploit | Cisco Smart License Utility | 4/9/2024 | 17/6/2026 | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful… |