Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Ecdsautils Project EcdsautilsFedoraproject FedoraDebian Linux6/5/202217/6/2026
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple…
ModificadaMedia (5.3)1.9%—Samba Cifs-utilsFedoraproject FedoraDebian Linux28/4/202217/6/2026
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
ModificadaAlta (7.8)0.58%—Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+1527/4/202217/6/2026
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
ModificadaAlta (7.5)1.4%—Springtree Madlib-object-utils15/4/202217/6/2026
The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676)
ModificadaAlta (8.1)1.3%—Nim-lang DocutilsNim-lang Nimforum1/2/202217/6/2026
Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview"…
ModificadaMedia (5.5)0.97%—GNU RecutilsFedoraproject Fedora14/1/202217/6/2026
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
ModificadaMedia (5.5)0.95%—GNU RecutilsFedoraproject Fedora14/1/202217/6/2026
An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
ModificadaMedia (5.5)1.0%—GNU RecutilsFedoraproject Fedora14/1/202217/6/2026
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
ModificadaAlta (7.8)1.3%—GNU BinutilsFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+115/12/202117/6/2026
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
ModificadaCrítica (9.8)0.87%—Utils.js Project Utils.js8/12/202117/6/2026
utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
ModificadaAlta (7.8)0.88%—GNU BinutilsGNU GCC18/11/202117/6/2026
GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.
ModificadaCrítica (9.8)4.3%💥 PoCCron-utils Project Cron-utils15/11/202117/6/2026
cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE)…
ModificadaCrítica (9.8)3.5%—Apache Ddlutils30/9/202117/6/2026
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used ObjectInputStream.readObject without…
ModificadaMedia (6.5)1.0%—GNU InetutilsDebian Linux3/9/202117/6/2026
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
ModificadaCrítica (9.8)1.0%—Lutils Project Lutils17/6/202117/6/2026
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.
ModificadaAlta (8.8)3.2%—Freedesktop Xdg-utilsDebian Linux2/6/202117/6/2026
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
ModificadaAlta (7.5)2.4%—GNU BinutilsNetapp Ontap Select Deploy Administration Utility2/6/202117/6/2026
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
ModificadaMedia (6.5)1.4%—Freedesktop Xdg-utils1/6/202117/6/2026
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a…
ModificadaAlta (7.1)0.97%—GNU Binutils26/5/202117/6/2026
An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system…
ModificadaAlta (7.8)3.3%💥 PoCGNU Binutils29/4/202117/6/2026
A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.
ModificadaMedia (6.1)0.67%—Samba Cifs-utilsRedhat Enterprise LinuxFedoraproject Fedora19/4/202117/6/2026
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
RechazadaSin puntuar——GNU BinutilsAI15/4/202120/11/2023
Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binutils-gdb/tree/binutils/SECURITY.txt
ModificadaMedia (5.5)1.3%—GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility26/3/202117/6/2026
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
ModificadaMedia (6.3)0.30%—GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+226/3/202117/6/2026
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities…
ModificadaMedia (5.6)3.3%—Facebook React-dev-utils9/3/202117/6/2026
react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this function is manually invoked with…
Orbitaley — Vulnerabilidades