Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.98% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.2% | — | FfmpegFedoraproject Fedora | 17/4/2024 | 17/6/2026 | FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function. | |
| Analizada | Media (6.1) | 0.89% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (4.3) | 0.92% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (4.3) | 0.85% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (4.3) | 0.72% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low) | |
| Analizada | Media (4.3) | 0.65% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Media (6.1) | 0.73% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) | |
| Analizada | Alta (7.5) | 0.85% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 18% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeFedoraproject Fedora | 17/4/2024 | 17/6/2026 | Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.9) | 0.42% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+3 | 16/4/2024 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL… | |
| Analizada | Alta (8.8) | 1.1% | — | Net-snmpDebian LinuxFedoraproject Fedora | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and… | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3… | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong… | |
| Analizada | Media (6.5) | 1.0% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch.… | |
| Analizada | Media (5.3) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use… | |
| Analizada | Alta (8.8) | 1.3% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users… | |
| Modificada | Media (5.9) | 5.8% | 💥 PoC | PuttyFilezilla-project Filezilla ClientWinscpTortoisegit+2 | 15/4/2024 | 17/6/2026 | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of… | |
| Analizada | Alta (7.5) | 0.96% | — | PydanticFedoraproject Fedora | 15/4/2024 | 17/6/2026 | Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string. | |
| Modificada | Alta (8) | 0.40% | — | FfmpegFedoraproject Fedora | 12/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component. | |
| Modificada | Alta (7) | 1.9% | — | EventletDnspythonFedoraproject FedoraNetapp Bootstrap OS | 11/4/2024 | 17/6/2026 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name… | |
| Modificada | Media (6.5) | 1.0% | — | Google ChromeFedoraproject Fedora | 10/4/2024 | 17/6/2026 | Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.79% | — | Google ChromeFedoraproject Fedora | 10/4/2024 | 17/6/2026 | Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.6) | 0.85% | — | Google ChromeFedoraproject Fedora | 10/4/2024 | 17/6/2026 | Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High) |