Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.2%—Facebook Hhvm4/12/201917/6/2026
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
ModificadaAlta (7.5)1.4%—Facebook Mcrouter4/12/201917/6/2026
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.
ModificadaAlta (7.5)1.5%—Facebook Mcrouter4/12/201917/6/2026
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.
ModificadaCrítica (9.8)1.6%—Facebook Hhvm19/11/201917/6/2026
hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
ModificadaAlta (7.2)2.0%—HP 260 G1 DM FirmwareHP 280 PRO G1 FirmwareHP 285 G2 FirmwareHP 340 G3 Firmware+985/11/201917/6/2026
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management…
ModificadaMedia (5.3)1.4%—Jupyter Notebook31/10/201917/6/2026
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
ModificadaCrítica (9.8)4.0%—Facebook Hhvm2/10/201917/6/2026
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0,…
ModificadaCrítica (9.8)2.3%—Facebook Hhvm6/9/201917/6/2026
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2,…
ModificadaCrítica (9.8)2.1%—Facebook Hhvm6/9/201917/6/2026
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and…
ModificadaAlta (8.8)0.69%—Facebook FOR Woocommerce30/8/201917/6/2026
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
ModificadaAlta (8.8)0.69%—Facebook FOR Woocommerce30/8/201917/6/2026
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
ModificadaAlta (7.5)12%💥 ExploitZedna Ebook Download Project Zedna Ebook Download22/8/201917/6/2026
The ebook-download plugin before 1.2 for WordPress has directory traversal.
ModificadaAlta (7.5)2.4%—Facebook Fizz20/8/201917/6/2026
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.
ModificadaAlta (7.5)3.7%—Sigil-ebook SigilFlightcrew Project FlightcrewCanonical Ubuntu Linux31/7/201917/6/2026
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
ModificadaAlta (8.1)1.4%—Facebook Zstandard25/7/201917/6/2026
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
ModificadaCrítica (9.8)2.1%—Facebook Proxygen25/7/201917/6/2026
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.
ModificadaCrítica (9.8)1.7%—Facebook Hiphop Virtual Machine18/7/201917/6/2026
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would attempt to verify it by re-running…
ModificadaAlta (7.5)1.5%—Facebook Hhvm26/6/201917/6/2026
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below,…
ModificadaAlta (7.5)2.8%—Facebook Thrift6/5/201917/6/2026
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to…
ModificadaAlta (7.5)2.0%—Facebook Thrift6/5/201917/6/2026
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior…
ModificadaCrítica (9.8)1.7%—Facebook Wangle29/4/201917/6/2026
Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00
ModificadaCrítica (9.8)1.7%—Facebook Hhvm29/4/201917/6/2026
Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).