Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1280 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.55%—Kernel Util-linux22/8/202317/6/2026
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
ModificadaMedia (5.5)0.33%—GNU Binutils22/8/202317/6/2026
An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.
ModificadaMedia (5.5)0.24%—Elfutils Project Elfutils22/8/202317/6/2026
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft…
ModificadaAlta (8.8)0.75%—GNU Binutils22/8/202317/6/2026
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
ModificadaMedia (5.5)0.30%—GNU Binutils22/8/202317/6/2026
A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.
ModificadaAlta (7.8)0.41%—GNU Inetutils14/8/202317/6/2026
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the…
ModificadaAlta (7.3)0.17%—Intel Server Firmware Update Utility11/8/202317/6/2026
Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.22%—Siemens JT Open ToolkitSiemens JT Utilities8/8/202317/6/2026
A vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current…
ModificadaAlta (7.8)0.22%—Siemens JT OpenSiemens JT UtilitiesSiemens Parasolid8/8/202317/6/2026
A vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4), Parasolid V34.0 (All versions < V34.0.253), Parasolid V34.1 (All versions < V34.1.243), Parasolid V35.0 (All versions < V35.0.177), Parasolid V35.1 (All versions < V35.1.073). The affected applications contain…
AnalizadaCrítica (9.8)0.57%—CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+425/7/202317/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of…
ModificadaMedia (5.5)0.29%—Elfutils Project Elfutils18/7/202317/6/2026
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
ModificadaMedia (6.5)0.75%—GNU Binutils18/7/202317/6/2026
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.
ModificadaAlta (7.5)2.0%—ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+217/7/202317/6/2026
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
ModificadaMedia (5.3)0.62%—OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility14/7/202317/6/2026
Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding…
ModificadaAlta (7.5)0.73%—Pwall Jsonutil14/6/202317/6/2026
An issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.8)0.71%—Erofs-utils Project Erofs-utils1/6/202317/6/2026
Heap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.
ModificadaAlta (7.8)0.81%—Erofs-utils Project Erofs-utils1/6/202317/6/2026
Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.
ModificadaCrítica (9.8)0.99%—Antfu Utils30/5/202317/6/2026
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
ModificadaMedia (6.5)0.90%—GNU Binutils17/5/202317/6/2026
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
ModificadaAlta (8.8)1.0%—Jenkins Pipeline Utility Steps16/5/202317/6/2026
An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.
ModificadaMedia (5.3)2.5%—Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython19/4/202317/6/2026
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after…
ModificadaAlta (7.8)0.22%—Siemens JT Open ToolkitSiemens JT Utilities11/4/202317/6/2026
A vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the…
ModificadaAlta (7.8)0.49%—GNU Binutils3/4/202317/6/2026
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
ModificadaAlta (8.8)0.61%—Go-huge-util Project Go-huge-util16/3/202317/6/2026
go-used-util has commonly used utility functions for Go. Versions prior to 0.0.34 have a ZipSlip issue when using fsutil package to unzip files. When users use `zip.Unzip` to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. The issue has been fixed in version 0.0.34. There are no…
ModificadaMedia (6.1)0.57%—Mobilevikings Django Ajax Utilities10/3/202317/6/2026
A vulnerability was found in Mobile Vikings Django AJAX Utilities up to 1.2.1 and classified as problematic. This issue affects the function Pagination of the file django_ajax/static/ajax-utilities/js/pagination.js of the component Backslash Handler. The manipulation of the argument url leads to cross site scripting.…