Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 1.2% | 💥 PoC | Libpng PngcheckFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 8/12/2020 | 17/6/2026 | A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 PoC | Airforce Nitf Extract Utility | 25/9/2020 | 17/6/2026 | U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow in a global variable (sBuffer) leads to a Write-What-Where outcome. Writing beyond sBuffer will clobber most global variables until reaching a pointer such as DES_info or image_info. By controlling… | |
| Modificada | Alta (7.8) | 0.34% | — | Sun-denshi Universal Forensic Extraction Device Firmware | 15/5/2020 | 17/6/2026 | Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen. | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Alta (7.5) | 1.0% | — | Apple Nioextras | 11/5/2020 | 17/6/2026 | In SwiftNIO Extras before 1.4.1, a logic issue was addressed with improved restrictions. | |
| Modificada | Baja (3.3) | 0.37% | — | KDE Kio-extras | 9/5/2020 | 17/6/2026 | fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password. | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Pureftpd Pure-ftpdDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+1 | 26/2/2020 | 17/6/2026 | An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member.… | |
| Modificada | Media (5.5) | 0.38% | — | Git-extras Project Git-extras | 28/1/2020 | 16/6/2026 | The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort. | |
| Modificada | Media (6.1) | 2.2% | — | CactiDebian LinuxOpensuse Backports SLEOpensuse Leap+3 | 16/1/2020 | 17/6/2026 | Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS). | |
| Modificada | Crítica (9.8) | 69% | 💥 PoC | Apache Log4jDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+13 | 20/12/2019 | 17/6/2026 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. | |
| Modificada | Media (5.3) | 2.3% | — | Cabextract Project Cabextract | 29/11/2019 | 17/6/2026 | cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.8) | 2.0% | — | Investintech Able2extract | 5/11/2019 | 17/6/2026 | An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a… | |
| Modificada | Alta (7.8) | 2.0% | — | Investintech Able2extract | 5/11/2019 | 17/6/2026 | An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this vulnerability by sending the user a specially… | |
| Modificada | Alta (8.8) | 1.9% | — | Elegantthemes Extra | 20/9/2019 | 17/6/2026 | The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation. | |
| Modificada | Alta (7.5) | 1.4% | — | Oceanwp Ocean Extra | 11/9/2019 | 17/6/2026 | includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence. | |
| Modificada | Alta (7.5) | 2.4% | — | Sinaextra Sina Extension FOR Elementor | 30/8/2019 | 17/6/2026 | The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. | |
| Modificada | Media (6.5) | 1.7% | — | GNU LibextractorDebian LinuxFedoraproject Fedora | 23/8/2019 | 17/6/2026 | GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c. | |
| Modificada | Alta (7.5) | 1.5% | — | Metadataextractor Project Metadataextractor | 25/7/2019 | 17/6/2026 | MetadataExtractor 2.1.0 allows stack consumption. | |
| Modificada | Alta (8.8) | 2.5% | — | Nextcloud Extract | 5/6/2019 | 17/6/2026 | lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters). | |
| Modificada | Media (6.5) | 2.2% | — | GNU LibextractorDebian Linux | 24/12/2018 | 17/6/2026 | GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c. | |
| Modificada | Media (6.5) | 2.2% | — | GNU LibextractorDebian Linux | 24/12/2018 | 17/6/2026 | GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c. | |
| Modificada | Media (6.5) | 3.1% | — | Cabextract Project CabextractLibmspack Project LibmspackDebian LinuxRedhat Enterprise Linux+3 | 23/10/2018 | 17/6/2026 | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write. | |
| Modificada | Alta (8.8) | 2.6% | — | GNU LibextractorDebian Linux | 4/9/2018 | 17/6/2026 | GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. |