Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 1.1% | — | Gnupg LibgcryptAI | 6/3/2024 | 17/6/2026 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts. | |
| Analizada | Media (4.9) | 0.91% | — | GNU Cpio | 29/2/2024 | 17/6/2026 | Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames. | |
| Analizada | Crítica (9.8) | 0.66% | — | Keerti1924 PHP Mysql User Signup Login System | 21/2/2024 | 17/6/2026 | A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /edit.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Crítica (9.8) | 0.81% | — | Keerti1924 PHP Mysql User Signup Login System | 21/2/2024 | 17/6/2026 | A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.4) | 0.58% | — | Keerti1924 PHP Mysql User Signup Login System | 21/2/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument username with the input <script>alert("xss")</script> leads to cross site scripting. It is possible to launch the… | |
| Modificada | Baja (3.3) | 0.27% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 6/2/2024 | 17/6/2026 | A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may… | |
| Modificada | Media (5.5) | 0.31% | — | GNU Indent | 6/2/2024 | 17/6/2026 | A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash. | |
| Modificada | Media (5.5) | 0.49% | 💥 PoC | GNU Coreutils | 6/2/2024 | 17/6/2026 | A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service. | |
| Modificada | Media (5.3) | 0.90% | — | GNU CpioRedhat Enterprise Linux | 5/2/2024 | 17/6/2026 | A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in… | |
| Modificada | Media (5.3) | 2.7% | — | GNU GlibcFedoraproject Fedora | 31/1/2024 | 17/6/2026 | An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in… | |
| Modificada | Alta (7.5) | 3.2% | — | GNU GlibcFedoraproject Fedora | 31/1/2024 | 17/6/2026 | An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to… | |
| Modificada | Alta (7.8) | 4.8% | 💥 PoC | GNU GlibcFedoraproject Fedora | 31/1/2024 | 17/6/2026 | A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is… | |
| Modificada | Alta (7.5) | 1.4% | — | GnutlsFedoraproject FedoraNetapp Active IQ Unified ManagerDebian Linux | 16/1/2024 | 17/6/2026 | A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack. | |
| Modificada | Alta (7.5) | 1.6% | — | GnutlsFedoraproject FedoraRedhat Enterprise Linux | 16/1/2024 | 17/6/2026 | A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading… | |
| Modificada | Media (6.8) | 0.54% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 15/1/2024 | 17/6/2026 | An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a… | |
| Modificada | Alta (7.5) | 0.54% | — | GNU Libredwg | 2/1/2024 | 17/6/2026 | Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c. | |
| Modificada | Alta (7.2) | 0.96% | — | Alphabpo Easy Newsletter Signups | 4/12/2023 | 17/6/2026 | The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Analizada | Media (5.9) | 1.3% | — | Debian LinuxGnutlsRedhat LinuxFedoraproject Fedora | 28/11/2023 | 17/6/2026 | A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. | |
| Modificada | Media (6.7) | 0.24% | — | GNU GrubXEN | 10/11/2023 | 17/6/2026 | An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation. | |
| Modificada | Media (4.6) | 0.49% | — | GNU Grub2Redhat Enterprise Linux | 25/10/2023 | 21/7/2026 | An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting… | |
| Modificada | Alta (7.8) | 0.54% | — | GNU Grub2Redhat Enterprise Linux | 25/10/2023 | 21/7/2026 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code… | |
| Modificada | Alta (8.8) | 0.25% | — | Laposta Signup Basic | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Alta (7.1) | 0.41% | — | GNU GawkRedhat Enterprise LinuxFedoraproject Fedora | 25/9/2023 | 17/6/2026 | A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information. | |
| Modificada | Alta (7.5) | 1.6% | — | GNU GlibcRedhat Enterprise Linux | 25/9/2023 | 17/6/2026 | A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash. |