Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

341 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.8%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
ModificadaMedia (6.5)3.7%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
ModificadaMedia (6.5)3.3%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
ModificadaMedia (6.5)1.7%—Debian LinuxGNU Libextractor17/7/201817/6/2026
GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
ModificadaAlta (8.8)2.1%—Debian LinuxGNU Libextractor17/7/201817/6/2026
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
ModificadaAlta (8.1)1.8%—Clang-extra Project Clang-extra4/6/201817/6/2026
The clang-extra module installs LLVM's clang-extra tools. clang-extra downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or…
ModificadaAlta (7)0.21%—Canonical Screen-resolution-extraCanonical Ubuntu Linux28/3/201817/6/2026
screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.
ModificadaMedia (6.5)2.4%—GNU Libextractor6/12/201717/6/2026
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
ModificadaMedia (5.5)1.3%—GNU Libextractor26/10/201717/6/2026
In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
ModificadaAlta (7.5)1.5%—GNU Libextractor18/10/201717/6/2026
In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.
ModificadaAlta (7.5)1.6%—GNU Libextractor18/10/201717/6/2026
In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to processiTXt and stndup.
ModificadaAlta (7.5)2.1%—GNU Libextractor18/10/201717/6/2026
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.
ModificadaAlta (7.5)2.6%—GNU Libextractor11/10/201717/6/2026
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.
ModificadaMedia (5.5)1.4%—GNU Libextractor11/10/201717/6/2026
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (5.9)0.49%—Forextrader5/5/201717/6/2026
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaCrítica (9.8)90%💥 ExploitApache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaAlta (7.8)2.1%—Textract Project Textract6/4/201717/6/2026
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
ModificadaAlta (7.5)5.9%💥 ExploitExtraputty27/3/201717/6/2026
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.
ModificadaMedia (5.4)1.2%—Jenkins Extra Columns9/2/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.
ModificadaAlta (7.5)2.8%—Agilent Technologies Feature Extraction9/3/201517/6/2026
The AnnotationX.AnnList.1 ActiveX control in Agilent Technologies Feature Extraction allows remote attackers to execute arbitrary code via a crafted object parameter in the Insert function, related to "Index Out-Of-Bounds."
ModificadaMedia (4.3)2.1%—URS Wolfer KwebkitpartKde-runtimeKDE Kio-extrasOpensuse8/12/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8)…
ModificadaMedia (6.8)0.71%—Pedro Cambra Commerce Extra Panes3/12/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Commerce Extra Panes module 7.x-1.x before 7.x-1.1 in Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable a Commerce extra panes pane via unspecified vectors related to "the link to reorder items."
ModificadaBaja (3.3)0.31%—Debian Texlive-extra-utils18/5/201216/6/2026
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
ModificadaAlta (9.3)7.5%💥 ExploitInvestintech Able2extractInvestintech Able2extract Server1/11/201116/6/2026
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.