Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

6914 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.72%—Google ChromeFedoraproject Fedora20/3/202417/6/2026
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.65%—Google ChromeFedoraproject Fedora20/3/202417/6/2026
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.88%—Google ChromeFedoraproject Fedora20/3/202417/6/2026
Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.82%—Google ChromeFedoraproject Fedora20/3/202417/6/2026
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)21%—Google ChromeFedoraproject Fedora20/3/202417/6/2026
Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.5)1.4%—Latchset JoseFedoraproject Fedora20/3/202417/6/2026
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
ModificadaMedia (6.5)0.27%—Fedoraproject FedoraXEN20/3/202417/6/2026
Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to protect against Return Oriented Programming attacks. When enabled, traditional stacks holding both data and return addresses are accompanied by…
AnalizadaMedia (4.1)0.26%—XENFedoraproject Fedora20/3/202417/6/2026
Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out of Xen.
AnalizadaMedia (5.3)0.80%—XENFedoraproject Fedora20/3/202417/6/2026
PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend the number of outstanding requests. Such phantom functions need an IOMMU context setup, but failure to…
AnalizadaAlta (7.5)1.1%—Libdwarf Project LibdwarfRedhat Enterprise LinuxFedoraproject Fedora18/3/202417/6/2026
A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.
ModificadaAlta (7.5)23%💥 PoCApache TomcatDebian LinuxFedoraproject Fedora13/3/202417/6/2026
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects…
ModificadaMedia (6.3)2.3%—Apache TomcatDebian LinuxFedoraproject Fedora13/3/202417/6/2026
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85,…
AnalizadaAlta (8.8)0.71%—Google ChromeFedoraproject Fedora13/3/202417/6/2026
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.5)0.67%—Broadcom TcpreplayFedoraproject Fedora12/3/202417/6/2026
Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.
AnalizadaCrítica (9.8)0.62%—Gacjie Server Project Gacjie Server12/3/202417/6/2026
A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaAlta (7.5)2.0%💥 PoCLibexpat Project LibexpatFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+1010/3/202417/6/2026
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
AnalizadaAlta (7.4)0.74%—Kozea WeasyprintFedoraproject Fedora9/3/202417/6/2026
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
AnalizadaMedia (4.3)2.0%—Go-jose Project Go-joseFedoraproject Fedora9/3/202417/6/2026
Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data…
AnalizadaMedia (5.9)2.1%—Jose Project JoseFedoraproject Fedora9/3/202417/6/2026
jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces,…
ModificadaMedia (6.5)1.5%—Apple SafariApple IpadosApple Iphone OSApple Macos+68/3/202417/6/2026
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
ModificadaMedia (6.5)1.3%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+58/3/202417/6/2026
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
ModificadaMedia (6.5)1.5%—Apple SafariApple IpadosApple Iphone OSApple Macos+68/3/202417/6/2026
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
ModificadaMedia (6.5)1.3%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+68/3/202417/6/2026
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
AnalizadaCrítica (9.9)79%💥 ExploitPgadmin 4Fedoraproject Fedora7/3/202417/6/2026
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an…
AnalizadaAlta (7.5)2.5%—Nlnetlabs UnboundFedoraproject Fedora7/3/202417/6/2026
NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size.…