Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Linuxfoundation OnnxFedoraproject Fedora | 23/2/2024 | 17/6/2026 | Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882. | |
| Analizada | Media (5.5) | 0.35% | — | C-aresFedoraproject Fedora | 23/2/2024 | 17/6/2026 | c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL`… | |
| Modificada | Media (6.5) | 1.2% | 💥 PoC | Debian LinuxFedoraproject FedoraRedhat Enterprise LinuxW1.fi WPA Supplicant | 22/2/2024 | 17/6/2026 | The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The… | |
| Analizada | Alta (7.5) | 1.0% | — | OpenvswitchFedoraproject Fedora | 22/2/2024 | 17/6/2026 | A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled. | |
| Modificada | Alta (7.5) | 1.3% | — | WiresharkFedoraproject Fedora | 21/2/2024 | 17/6/2026 | A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | |
| Modificada | Alta (7.5) | 1.3% | — | Fedoraproject FedoraWireshark | 21/2/2024 | 17/6/2026 | A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | |
| Analizada | Media (4.3) | 0.85% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+3 | 21/2/2024 | 17/6/2026 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing. | |
| Analizada | Media (5.4) | 19% | — | Google ChromeFedoraproject Fedora | 21/2/2024 | 17/6/2026 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Alta (8.8) | 11% | — | Google ChromeFedoraproject Fedora | 21/2/2024 | 17/6/2026 | Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.79% | — | Google ChromeFedoraproject Fedora | 21/2/2024 | 17/6/2026 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 0.80% | — | Google ChromeFedoraproject Fedora | 21/2/2024 | 17/6/2026 | Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium) | |
| Analizada | Media (5.4) | 0.89% | — | Google ChromeFedoraproject Fedora | 21/2/2024 | 17/6/2026 | Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 9.1% | — | Google ChromeFedoraproject Fedora | 21/2/2024 | 17/6/2026 | Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.96% | — | Google ChromeFedoraproject Fedora | 21/2/2024 | 17/6/2026 | Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.8) | 1.7% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.8% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger… | |
| Modificada | Crítica (9.8) | 1.7% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.6% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.8% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger… | |
| Modificada | Crítica (9.8) | 1.8% | — | Libbiosig Project LibbiosigFedoraproject Fedora | 20/2/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 1.2% | — | Agronholm Cbor2Fedoraproject Fedora | 19/2/2024 | 17/6/2026 | cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this… | |
| Analizada | Media (5.3) | 0.60% | — | MoodleFedoraproject Fedora | 19/2/2024 | 17/6/2026 | Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). | |
| Analizada | Alta (8.8) | 0.50% | — | MoodleFedoraproject Fedora | 19/2/2024 | 17/6/2026 | The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. |