Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.75%—GNU Binutils29/1/202517/6/2026
A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack…
AplazadaMedia (6.2)0.36%—GNU C LibraryAI22/1/202517/6/2026
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
AplazadaMedia (5.5)0.25%—GNU BinutilsAI21/1/202517/6/2026
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
AnalizadaMedia (5.3)0.40%—GNU Grub229/12/202417/6/2026
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
AnalizadaAlta (8.8)0.72%—GNU Grub229/12/202417/6/2026
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.
AplazadaMedia (6.5)0.54%—Alphabpo Easy Newsletter SignupsAI13/12/202417/6/2026
Missing Authorization vulnerability in AlphaBPO Easy Newsletter Signups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Newsletter Signups: from n/a through 1.0.4.
AplazadaAlta (8.4)0.27%—GNU ObjdumpAIGNU BFDAI5/12/202417/6/2026
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
ModificadaAlta (7.8)0.60%—GNU Emacs27/11/202421/9/2026
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly…
AplazadaMedia (6.5)0.37%—Riley Magnuson MyorderdeskAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riley Magnuson MyOrderDesk myorderdesk allows DOM-Based XSS.This issue affects MyOrderDesk: from n/a through <= 3.2.6.
AplazadaMedia (6.5)1.1%—GNU WgetAI19/11/202417/6/2026
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
AplazadaAlta (8.1)0.23%—GNU GuixAI17/11/202417/6/2026
guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, and restart actions.…
AplazadaAlta (7)0.32%—GNU Grub2AI13/11/202417/6/2026
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
AplazadaCrítica (9.8)1.3%💥 PoCScott Gamon Signup PageAI29/10/202417/6/2026
Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0.
AnalizadaBaja (3.6)0.28%—GNU Scientific Library27/10/202417/6/2026
GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.
AnalizadaCrítica (9.8)3.3%💥 ExploitWow-company Viral Signup4/9/202417/6/2026
The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
AnalizadaMedia (4.8)0.37%—Wow-company Viral Signup29/8/202417/6/2026
The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.39%—SIR Gnuboard26/8/202417/6/2026
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
AnalizadaAlta (8.8)0.29%—SIR Gnuboard12/8/202417/6/2026
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
AnalizadaCrítica (9.8)1.3%—GNU Emacs23/6/202417/6/2026
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
AplazadaCrítica (9.1)0.53%—GNU GlobalAI16/6/202417/6/2026
htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.
ModificadaCrítica (9.1)0.67%—GNU Wget16/6/202417/6/2026
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
AnalizadaAlta (8.4)0.36%—GNU Libcdio14/6/202417/6/2026
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
ModificadaMedia (6.7)0.34%—GNU NanoRedhat Enterprise Linux12/6/202417/6/2026
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious…
ModificadaMedia (4.3)0.36%—Xootix Login/signup Popup6/6/202417/6/2026
The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read…
ModificadaAlta (8.8)1.5%💥 PoCXootix Login/signup PopupXootix OTP Login Woocommerce & Gravity FormsXootix Side Cart WoocommerceXootix Waitlist Woocommerce6/6/202417/6/2026
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary…