Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

424 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)2.2%—CactiDebian LinuxOpensuse Backports SLEOpensuse Leap+316/1/202017/6/2026
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+310/1/202017/6/2026
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)16%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora10/1/202017/6/2026
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (5.3)1.5%—OtrsDebian LinuxOpensuse Backports SLEOpensuse Leap10/1/202017/6/2026
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions.…
ModificadaMedia (6.5)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
ModificadaAlta (8.1)1.7%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
ModificadaAlta (8.1)1.7%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
ModificadaAlta (8.1)1.7%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
ModificadaMedia (6.5)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse BackportsOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
ModificadaAlta (8.8)1.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap8/1/202017/6/2026
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
ModificadaMedia (4.3)1.6%—OtrsDebian LinuxOpensuse Backports SLEOpensuse Leap6/1/202017/6/2026
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
ModificadaMedia (6.5)1.4%—Google ChromeOpensuse Backports SLEOpensuse Leap3/1/202017/6/2026
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.4%—Google ChromeOpensuse Backports SLEOpensuse Leap3/1/202017/6/2026
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.4%—Google ChromeOpensuse Backports SLEOpensuse Leap3/1/202017/6/2026
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.9%—Redhat AnsibleRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+42/1/202017/6/2026
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
ModificadaMedia (5.5)1.2%—UPXOpensuse BackportsOpensuse Leap27/12/201917/6/2026
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
ModificadaAlta (8.8)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
ModificadaAlta (8.8)1.5%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
ModificadaAlta (8.8)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
ModificadaMedia (6.5)1.4%—GNU LibredwgOpensuse Backports SLEOpensuse Leap27/12/201917/6/2026
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
ModificadaAlta (7.5)6.8%—SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+724/12/201917/6/2026
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.