Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Ecdsautils Project EcdsautilsFedoraproject FedoraDebian Linux | 6/5/2022 | 17/6/2026 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple… | |
| Modificada | Media (5.3) | 1.9% | — | Samba Cifs-utilsFedoraproject FedoraDebian Linux | 28/4/2022 | 17/6/2026 | cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file. | |
| Modificada | Alta (7.8) | 0.58% | — | Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+15 | 27/4/2022 | 17/6/2026 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. | |
| Modificada | Alta (7.5) | 1.4% | — | Springtree Madlib-object-utils | 15/4/2022 | 17/6/2026 | The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676) | |
| Modificada | Alta (8.1) | 1.3% | — | Nim-lang DocutilsNim-lang Nimforum | 1/2/2022 | 17/6/2026 | Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview"… | |
| Modificada | Media (5.5) | 0.97% | — | GNU RecutilsFedoraproject Fedora | 14/1/2022 | 17/6/2026 | An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | |
| Modificada | Media (5.5) | 0.95% | — | GNU RecutilsFedoraproject Fedora | 14/1/2022 | 17/6/2026 | An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | |
| Modificada | Media (5.5) | 1.0% | — | GNU RecutilsFedoraproject Fedora | 14/1/2022 | 17/6/2026 | An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | |
| Modificada | Alta (7.8) | 1.3% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+1 | 15/12/2021 | 17/6/2026 | stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699. | |
| Modificada | Crítica (9.8) | 0.87% | — | Utils.js Project Utils.js | 8/12/2021 | 17/6/2026 | utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Modificada | Alta (7.8) | 0.88% | — | GNU BinutilsGNU GCC | 18/11/2021 | 17/6/2026 | GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c. | |
| Modificada | Crítica (9.8) | 4.3% | 💥 PoC | Cron-utils Project Cron-utils | 15/11/2021 | 17/6/2026 | cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE)… | |
| Modificada | Crítica (9.8) | 3.5% | — | Apache Ddlutils | 30/9/2021 | 17/6/2026 | Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used ObjectInputStream.readObject without… | |
| Modificada | Media (6.5) | 1.0% | — | GNU InetutilsDebian Linux | 3/9/2021 | 17/6/2026 | The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl. | |
| Modificada | Crítica (9.8) | 1.0% | — | Lutils Project Lutils | 17/6/2021 | 17/6/2026 | All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function. | |
| Modificada | Alta (8.8) | 3.2% | — | Freedesktop Xdg-utilsDebian Linux | 2/6/2021 | 17/6/2026 | The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file. | |
| Modificada | Alta (7.5) | 2.4% | — | GNU BinutilsNetapp Ontap Select Deploy Administration Utility | 2/6/2021 | 17/6/2026 | A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash. | |
| Modificada | Media (6.5) | 1.4% | — | Freedesktop Xdg-utils | 1/6/2021 | 17/6/2026 | A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a… | |
| Modificada | Alta (7.1) | 0.97% | — | GNU Binutils | 26/5/2021 | 17/6/2026 | An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system… | |
| Modificada | Alta (7.8) | 3.3% | 💥 PoC | GNU Binutils | 29/4/2021 | 17/6/2026 | A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability. | |
| Modificada | Media (6.1) | 0.67% | — | Samba Cifs-utilsRedhat Enterprise LinuxFedoraproject Fedora | 19/4/2021 | 17/6/2026 | A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity. | |
| Rechazada | Sin puntuar | — | — | GNU BinutilsAI | 15/4/2021 | 20/11/2023 | Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binutils-gdb/tree/binutils/SECURITY.txt | |
| Modificada | Media (5.5) | 1.3% | — | GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility | 26/3/2021 | 17/6/2026 | A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (6.3) | 0.30% | — | GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+2 | 26/3/2021 | 17/6/2026 | There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities… | |
| Modificada | Media (5.6) | 3.3% | — | Facebook React-dev-utils | 9/3/2021 | 17/6/2026 | react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this function is manually invoked with… |