Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.41% | — | SIR Gnuboard | 14/5/2024 | 17/6/2026 | Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. | |
| Modificada | Alta (7.4) | 0.40% | — | GNU GlibcDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+7 | 6/5/2024 | 17/6/2026 | nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present… | |
| Modificada | Alta (7.3) | 1.1% | — | GNU GlibcDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+7 | 6/5/2024 | 17/6/2026 | nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15… | |
| Modificada | Media (5.9) | 1.2% | — | GNU GlibcDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+8 | 6/5/2024 | 17/6/2026 | nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only… | |
| Modificada | Alta (8.1) | 1.3% | — | GNU GlibcDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 6/5/2024 | 17/6/2026 | nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This… | |
| Aplazada | Media (5.3) | 0.50% | — | Mailerlite Signup FormsAI | 2/5/2024 | 17/6/2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.42% | — | Mailerlite Signup FormsAI | 2/5/2024 | 17/6/2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| En análisis | Alta (7.3) | 88% | 💥 Exploit | GNU GlibcNetapp Active IQ Unified ManagerDebian LinuxNetapp HCI H300s Firmware+9 | 17/4/2024 | 17/6/2026 | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable. | |
| Analizada | Crítica (9.8) | 1.1% | — | Openstack Magnum | 12/4/2024 | 17/6/2026 | An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component. | |
| Analizada | Alta (7.6) | 0.95% | 💥 PoC | GNU Savane | 11/4/2024 | 17/6/2026 | An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component. | |
| Analizada | Alta (8.8) | 1.3% | 💥 PoC | GNU Savane | 8/4/2024 | 17/6/2026 | An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function. | |
| Analizada | Media (6) | 0.42% | 💥 PoC | GNU Savane | 8/4/2024 | 17/6/2026 | Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php | |
| Analizada | Alta (7.5) | 0.82% | 💥 PoC | GNU Savane | 8/4/2024 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function. | |
| Analizada | Media (6.7) | 0.38% | — | GNU Grub2Netapp Bootstrap OS | 5/4/2024 | 17/6/2026 | GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass. | |
| Aplazada | Sin puntuar | 0.32% | — | GNU Midnight CommanderAI | 27/3/2024 | 17/6/2026 | GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/x11conn.c. NOTE: this is disputed because it should be categorized as a usability problem (an X operation silently fails). | |
| Modificada | Media (6.2) | 0.28% | — | GNU TAR | 27/3/2024 | 17/6/2026 | In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c. | |
| Analizada | Alta (7.1) | 0.48% | — | GNU EmacsGNU ORG ModeDebian Linux | 25/3/2024 | 17/6/2026 | In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23. | |
| Analizada | Baja (2.8) | 0.47% | — | GNU EmacsGNU ORG ModeDebian Linux | 25/3/2024 | 17/6/2026 | In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. | |
| Analizada | Media (5.5) | 0.58% | — | GNU EmacsGNU ORG ModeDebian Linux | 25/3/2024 | 17/6/2026 | In Emacs before 29.3, Gnus treats inline MIME contents as trusted. | |
| Analizada | Alta (7.8) | 1.1% | — | GNU EmacsGNU ORG Mode | 25/3/2024 | 17/6/2026 | In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23. | |
| Aplazada | Media (5.3) | 0.72% | — | GnutlsAI | 21/3/2024 | 17/6/2026 | A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to… | |
| Aplazada | Media (5) | 0.39% | — | Gnutls CerttoolAIGnutlsAI | 21/3/2024 | 3/7/2026 | A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command. | |
| Analizada | Media (6.1) | 0.53% | — | SIR Gnuboard | 16/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter. | |
| Analizada | Alta (7.5) | 0.83% | — | Keerti1924 PHP Mysql User Signup Login System | 7/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive information in source code. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Crítica (9.8) | 0.60% | — | Keerti1924 PHP Mysql User Signup Login System | 7/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been… |