Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

424 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.8%—SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+724/12/201917/6/2026
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
ModificadaCrítica (9.1)2.8%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/12/201917/6/2026
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
ModificadaCrítica (9.8)2.5%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/12/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
ModificadaCrítica (9.8)2.7%—GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap24/12/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
ModificadaAlta (7.5)7.0%—SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+723/12/201917/6/2026
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
ModificadaAlta (7.8)1.6%—Lout Project LoutOpensuse Backports SLEFedoraproject FedoraOpensuse Leap20/12/201917/6/2026
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
ModificadaAlta (7.8)1.5%—Lout Project LoutOpensuse Backports SLEOpensuse LeapFedoraproject Fedora20/12/201917/6/2026
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
ModificadaAlta (7.5)6.9%—SqliteNetapp Cloud BackupDebian LinuxSuse Package HUB+718/12/201917/6/2026
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
AnalizadaMedia (5.9)1.4%—Excon Project ExconOpensuse Backports SLEOpensuse LeapDebian Linux16/12/201928/7/2026
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be…
ModificadaAlta (8.8)6.4%💥 PoCGoogle ChromeDebian LinuxFedoraproject FedoraSuse Package HUB+410/12/201917/6/2026
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeDebian LinuxSuse Package HUBOpensuse Backports SLE+410/12/201917/6/2026
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)3.9%—Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1110/12/201917/6/2026
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeDebian LinuxFedoraproject FedoraNovell Suse Package HUB FOR Suse Linux Enterprise+510/12/201917/6/2026
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7.8)0.76%—Shadowsocks-libevOpensuse Backports SLEOpensuse Leap3/12/201917/6/2026
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
ModificadaAlta (7.5)2.6%—Shadowsocks-libevOpensuse BackportsOpensuse Leap3/12/201917/6/2026
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.
ModificadaMedia (6.5)1.7%—Redhat AnsibleOpensuse Backports SLEOpensuse LeapRedhat Openstack26/11/201917/6/2026
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
ModificadaAlta (8.8)1.5%—Google ChromeFedoraproject FedoraOpensuse BackportsRedhat Enterprise Linux Desktop+225/11/201917/6/2026
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.2%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
ModificadaMedia (4.3)0.88%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
ModificadaMedia (4.3)1.0%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
ModificadaMedia (4.3)0.93%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (4.3)0.85%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
ModificadaMedia (6.1)0.83%—Google ChromeOpensuse Backports SLE25/11/201917/6/2026
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
ModificadaMedia (6.5)1.1%—Google ChromeOpensuse Backports25/11/201917/6/2026
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (5.3)1.2%—Google ChromeOpensuse Backports25/11/201917/6/2026
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.