Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.72% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.65% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.88% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.82% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 21% | — | Google ChromeFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.4% | — | Latchset JoseFedoraproject Fedora | 20/3/2024 | 17/6/2026 | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | |
| Modificada | Media (6.5) | 0.27% | — | Fedoraproject FedoraXEN | 20/3/2024 | 17/6/2026 | Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to protect against Return Oriented Programming attacks. When enabled, traditional stacks holding both data and return addresses are accompanied by… | |
| Analizada | Media (4.1) | 0.26% | — | XENFedoraproject Fedora | 20/3/2024 | 17/6/2026 | Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out of Xen. | |
| Analizada | Media (5.3) | 0.80% | — | XENFedoraproject Fedora | 20/3/2024 | 17/6/2026 | PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend the number of outstanding requests. Such phantom functions need an IOMMU context setup, but failure to… | |
| Analizada | Alta (7.5) | 1.1% | — | Libdwarf Project LibdwarfRedhat Enterprise LinuxFedoraproject Fedora | 18/3/2024 | 17/6/2026 | A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results. | |
| Modificada | Alta (7.5) | 23% | 💥 PoC | Apache TomcatDebian LinuxFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects… | |
| Modificada | Media (6.3) | 2.3% | — | Apache TomcatDebian LinuxFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85,… | |
| Analizada | Alta (8.8) | 0.71% | — | Google ChromeFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (6.5) | 0.67% | — | Broadcom TcpreplayFedoraproject Fedora | 12/3/2024 | 17/6/2026 | Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command. | |
| Analizada | Crítica (9.8) | 0.62% | — | Gacjie Server Project Gacjie Server | 12/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.5) | 2.0% | 💥 PoC | Libexpat Project LibexpatFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+10 | 10/3/2024 | 17/6/2026 | libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). | |
| Analizada | Alta (7.4) | 0.74% | — | Kozea WeasyprintFedoraproject Fedora | 9/3/2024 | 17/6/2026 | WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2. | |
| Analizada | Media (4.3) | 2.0% | — | Go-jose Project Go-joseFedoraproject Fedora | 9/3/2024 | 17/6/2026 | Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data… | |
| Analizada | Media (5.9) | 2.1% | — | Jose Project JoseFedoraproject Fedora | 9/3/2024 | 17/6/2026 | jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces,… | |
| Modificada | Media (6.5) | 1.5% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Modificada | Media (6.5) | 1.3% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+5 | 8/3/2024 | 17/6/2026 | An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user. | |
| Modificada | Media (6.5) | 1.5% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| Modificada | Media (6.5) | 1.3% | — | Apple SafariApple Ipad OSApple Iphone OSApple Macos+6 | 8/3/2024 | 17/6/2026 | The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin. | |
| Analizada | Crítica (9.9) | 79% | 💥 Exploit | Pgadmin 4Fedoraproject Fedora | 7/3/2024 | 17/6/2026 | pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an… | |
| Analizada | Alta (7.5) | 2.5% | — | Nlnetlabs UnboundFedoraproject Fedora | 7/3/2024 | 17/6/2026 | NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size.… |