Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1280 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.3)0.64%—GNU Binutils10/2/202517/6/2026
A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is…
ModificadaBaja (2.3)0.67%—GNU Binutils10/2/202517/6/2026
A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The…
AplazadaAlta (7.5)0.40%—Indeed UtilAI5/2/202517/6/2026
A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AplazadaAlta (7.5)0.44%—Cli-utilAI5/2/202517/6/2026
A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AplazadaCrítica (9.1)0.49%—Utils-extendAI5/2/202517/6/2026
The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence.
AplazadaAlta (7.5)0.40%—Xe-utilsAI5/2/202517/6/2026
A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AplazadaAlta (7.5)0.55%—UtileAI5/2/202517/6/2026
A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AnalizadaBaja (3.4)0.69%—Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+125/2/202517/6/2026
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
AnalizadaMedia (6.3)0.75%—GNU Binutils29/1/202517/6/2026
A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack…
AplazadaAlta (8.6)0.19%—Adobe Flash Programming UtilityAI24/1/202517/6/2026
DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
AplazadaMedia (5.5)0.25%—GNU BinutilsAI21/1/202517/6/2026
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
AplazadaMedia (6.4)0.28%—Utilities FOR MTGAI18/1/202517/6/2026
The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.5)0.38%—GIT Utilities Project GIT Utilities9/1/202517/6/2026
Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.
AplazadaBaja (3.6)0.43%💥 PoCShadow-utils ShadowAI26/12/202417/6/2026
shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap…
AnalizadaMedia (6.7)0.17%—Dell Dock Hd22q Firmware Update UtilityDell Dock Wd19 Firmware Update UtilityDell Dock Wd22tb4 Firmware Update Utility11/12/202417/6/2026
Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
ModificadaBaja (3.4)1.3%—Haxx CurlNetapp OntapNetapp Ontap Select Deploy Administration UtilityNetapp H610c Firmware+711/12/202417/6/2026
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either…
AplazadaMedia (6.5)0.16%—HPE Nonstop Disk UtilAI22/11/202417/6/2026
A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.
AnalizadaMedia (4.4)0.21%—Dell Intel Management Engine Firmware Update Utility22/11/202417/6/2026
Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this…
AnalizadaAlta (7.3)0.24%—AMD Ryzen Master Utility FOR Overclocking Control12/11/202417/6/2026
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AnalizadaMedia (5.3)0.30%—Iowacomputergurus Aspnetcore.utilities.cloudstorage30/10/202417/6/2026
ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than desired. Users not…
AnalizadaBaja (3.3)0.14%—Hashicorp Vagrant Vmware Utility29/10/202417/6/2026
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
AnalizadaMedia (5.9)1.0%💥 PoCNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+827/10/202417/6/2026
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
AplazadaMedia (6.3)0.76%—XZ UtilsAI2/10/202417/6/2026
XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerability. If a command line contains Unicode characters (for example, filenames) that…
AnalizadaMedia (6.5)0.73%—Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+611/9/202417/6/2026
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for…
AnalizadaAlta (7.5)52%💥 ExploitCisco Smart License Utility4/9/202417/6/2026
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful…