Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.16% | — | Freebsd | 21/5/2026 | 23/7/2026 | libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available. However, it does not verify that its socket descriptor fits within select(2)'s descriptor set size limit of FD_SETSIZE (1024). An attacker able to cause an application using… | |
| Modificada | Alta (7.8) | 0.19% | 💥 PoC | Freebsd | 21/5/2026 | 23/7/2026 | The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-size kernel stack buffer without first validating its length. If the supplied list exceeds the capacity of that buffer, a… | |
| Aplazada | Alta (8.6) | 0.97% | — | FreepbxAI | 18/5/2026 | 24/7/2026 | FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected files from a… | |
| Aplazada | Baja (2.1) | 0.53% | — | Free5gc AMFAI | 18/5/2026 | 17/6/2026 | A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabilityCheckResponse of the file ngap/dispatcher.go. Such manipulation leads to null pointer dereference. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.… | |
| Aplazada | Baja (2.1) | 0.53% | — | Free5gc AMFAI | 18/5/2026 | 17/6/2026 | A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/handler.go of the component NGAP Message Handler. This manipulation causes null pointer dereference. Remote exploitation of the attack is possible. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.53% | — | Free5gc AMFAI | 18/5/2026 | 17/6/2026 | A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfiguration of the file ngap/handler.go. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.… | |
| Aplazada | Baja (2.1) | 0.53% | — | Free5gc AMFAI | 18/5/2026 | 17/6/2026 | A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the file ngap/dispatcher.go of the component NGAP Message Handler. The manipulation leads to memory corruption. The attack may be initiated remotely. The exploit is publicly available and might be used.… | |
| Aplazada | Baja (2.1) | 0.53% | — | Free5gc AMFAI | 18/5/2026 | 17/6/2026 | A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Alta (8.7) | 0.68% | — | Freertos Coremqtt | 15/5/2026 | 17/6/2026 | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1. | |
| Analizada | Crítica (9.1) | 0.35% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Analizada | Media (5.5) | 0.14% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Freedesktop MalcontentAI | 13/5/2026 | 17/6/2026 | The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in malcontent-timerd allows arbitrary users in the system to slowly fill up disk space in /var/lib/malcontent-timerd | |
| Pendiente de análisis | Alta (7) | 0.16% | — | KDE PlasmaAIFreedesktop DbusAI | 13/5/2026 | 17/6/2026 | The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system. | |
| Aplazada | Baja (2.1) | 0.53% | — | Free5gc AMFAI | 12/5/2026 | 17/6/2026 | A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attack can be launched remotely. The exploit has been published and may be used. This patch is called… | |
| Aplazada | Alta (7.3) | 0.29% | — | Alien FreeimageAIFreeimageAI | 11/5/2026 | 17/6/2026 | Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have known vulnerabilities. | |
| Aplazada | Alta (7.1) | 0.29% | — | FreescoutAI | 7/5/2026 | 17/6/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filtered search endpoint, but the backend conversation_change_customer action accepts any supplied customer_email. A… | |
| Aplazada | Alta (7.7) | 0.35% | — | FreescoutAI | 7/5/2026 | 17/6/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but then re-validates the original URL instead of the final redirect destination. An attacker who can… | |
| Aplazada | Alta (7.6) | 0.30% | — | FreescoutAI | 7/5/2026 | 17/6/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply message. The payload is rendered unescaped in the auto-reply email sent to every customer who contacts the mailbox.… | |
| Aplazada | Media (5.4) | 0.36% | — | FreescoutAI | 7/5/2026 | 17/6/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended for general user-profile editing) can read and modify the notification subscriptions of any other user, including admins, by sending a single POST… | |
| Aplazada | Crítica (9.1) | 0.42% | — | FreescoutAI | 7/5/2026 | 17/6/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains valid indefinitely until consumed. Combined… | |
| Aplazada | Media (6.4) | 0.33% | — | WP Carousel FreeAI | 5/5/2026 | 17/6/2026 | The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-caption` attributes in all versions up to, and including, 2.7.10. This is due to the `fancybox-config.js` script reading the carousel container's `id` attribute directly from the DOM to construct a jQuery… | |
| Aplazada | Media (4.3) | 0.24% | — | AddfreespaceAI | 5/5/2026 | 17/6/2026 | The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged… | |
| Modificada | Alta (8.1) | 1.8% | — | Freebsd | 30/4/2026 | 17/6/2026 | As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to overrun its buffer of… | |
| Analizada | Alta (7.8) | 0.16% | — | Freebsd | 30/4/2026 | 17/6/2026 | When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large file descriptors, e.g.,… | |
| Modificada | Alta (8.1) | 0.40% | — | Freebsd | 30/4/2026 | 17/6/2026 | When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to… |