Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1280 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.69%—Codehaus-plexus Plexus-utilsRedhat Integration Camel K25/9/202317/6/2026
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
AnalizadaAlta (7.5)1.3%💥 PoCCodehaus-plexus Plexus-utilsRedhat Integration Camel K25/9/202317/6/2026
A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access…
ModificadaMedia (5.5)0.38%—GNU Binutils14/9/202317/6/2026
A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.
ModificadaMedia (5.5)0.35%—GNU Binutils14/9/202317/6/2026
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
ModificadaMedia (5.5)0.38%—GNU Binutils14/9/202317/6/2026
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
ModificadaAlta (7.1)0.38%—GNU Binutils14/9/202317/6/2026
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
ModificadaAlta (7.8)0.17%—Dell SD ROM Utility12/9/202317/6/2026
SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.
ModificadaAlta (7.8)0.38%💥 PoCFoxconn Live Update Utility11/9/202317/6/2026
An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.
ModificadaAlta (7.5)1.5%—Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+131/8/202317/6/2026
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest…
ModificadaMedia (5.5)0.64%—GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora22/8/202317/6/2026
GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.
ModificadaMedia (5.5)0.61%—GNU BinutilsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility22/8/202317/6/2026
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
ModificadaMedia (5.5)0.46%—GNU Binutils22/8/202317/6/2026
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
ModificadaAlta (7.8)0.42%—GNU Binutils22/8/202317/6/2026
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.
ModificadaAlta (7.8)0.45%—GNU Binutils22/8/202317/6/2026
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c.
ModificadaAlta (7.8)0.43%—GNU Binutils22/8/202317/6/2026
An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts.
ModificadaMedia (5.5)0.39%—GNU Binutils22/8/202317/6/2026
An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
ModificadaMedia (5.5)0.39%—GNU Binutils22/8/202317/6/2026
An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
ModificadaMedia (5.5)0.39%—GNU Binutils22/8/202317/6/2026
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
ModificadaMedia (5.5)0.40%—GNU Binutils22/8/202317/6/2026
An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
ModificadaAlta (7.8)0.51%—GNU Binutils22/8/202317/6/2026
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.
ModificadaAlta (7.8)0.49%—GNU Binutils22/8/202317/6/2026
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.
ModificadaMedia (5.5)0.34%—GNU Binutils22/8/202317/6/2026
Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.
ModificadaMedia (5.5)0.39%—GNU Binutils22/8/202317/6/2026
An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service.
ModificadaAlta (7.5)0.82%—GNU Binutils22/8/202317/6/2026
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
ModificadaAlta (7.5)0.77%—GNU Binutils22/8/202317/6/2026
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.