Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.3% | — | Google ChromeFedoraproject Fedora | 6/3/2024 | 17/6/2026 | Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 13% | — | Google ChromeFedoraproject Fedora | 6/3/2024 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 14% | — | Google ChromeFedoraproject Fedora | 6/3/2024 | 17/6/2026 | Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 65% | — | Squid-cache SquidFedoraproject FedoraNetapp Bluexp | 6/3/2024 | 17/6/2026 | Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP… | |
| Modificada | Alta (7.5) | 0.94% | — | Intel Inet Wireless DaemonFedoraproject Fedora | 3/3/2024 | 17/6/2026 | p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails. | |
| Modificada | Media (5.5) | 0.44% | — | Qpdf Project QpdfFedoraproject Fedora | 29/2/2024 | 17/6/2026 | Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h. | |
| Modificada | Alta (7.5) | 1.5% | — | ClojureFedoraproject Fedora | 29/2/2024 | 17/6/2026 | An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function. | |
| Modificada | Alta (8.6) | 1.8% | — | Ibireme YyjsonFedoraproject Fedora | 29/2/2024 | 17/6/2026 | yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.) | |
| Modificada | Media (6.1) | 0.56% | — | Http-swagger Project Http-swagger | 29/2/2024 | 17/6/2026 | http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request. NOTE: this is independently fixable with respect to CVE-2022-24863, because (if a solution continued to allow PUT requests)… | |
| Analizada | Alta (8.8) | 2.6% | 💥 PoC | Google ChromeFedoraproject Fedora | 29/2/2024 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.83% | — | Google ChromeFedoraproject Fedora | 29/2/2024 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.1) | 1.1% | — | Yardoc YardFedoraproject FedoraDebian Linux | 28/2/2024 | 17/6/2026 | YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36. | |
| Modificada | Alta (7.5) | 1.2% | — | LiblasFedoraproject Fedora | 27/2/2024 | 17/6/2026 | libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp. | |
| Modificada | Alta (7.5) | 0.99% | — | Reproducible Builds DiffoscopeFedoraproject Fedora | 27/2/2024 | 17/6/2026 | diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted. | |
| Modificada | Media (6.5) | 1.9% | 💥 PoC | FontforgeDebian LinuxFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. | |
| Modificada | Media (4.2) | 1.1% | 💥 PoC | FontforgeDebian LinuxFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Splinefont in FontForge through 20230101 allows command injection via crafted filenames. | |
| Analizada | Media (5.3) | 0.64% | — | Oisf SuricataFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3. | |
| Analizada | Alta (8.1) | 0.78% | — | Oisf SuricataFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To… | |
| Modificada | Alta (7.5) | 1.2% | — | Oisf LibhtpFedoraproject Fedora | 26/2/2024 | 17/6/2026 | LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46. | |
| Analizada | Alta (7.5) | 1.2% | — | Oisf SuricataFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CPU and memory for processing the traffic than needed, which can lead to extreme slow downs and… | |
| Analizada | Alta (7.5) | 0.93% | — | Oisf SuricataFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround, users can disable the pgsql app layer parser. | |
| Analizada | Alta (7.5) | 1.0% | — | Nlnetlabs RoutinatorFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening. | |
| Analizada | Media (5.3) | 1.0% | — | Apostrophecms Sanitize-htmlFedoraproject Fedora | 24/2/2024 | 17/6/2026 | Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system… | |
| Modificada | Crítica (9.1) | 0.59% | — | Linuxfoundation OnnxFedoraproject Fedora | 23/2/2024 | 17/6/2026 | Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy. | |
| Modificada | Alta (7.5) | 1.2% | — | Linuxfoundation OnnxFedoraproject Fedora | 23/2/2024 | 17/6/2026 | Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882. |