Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 10% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Baja (3.3) | 0.23% | — | Packagekit Project PackagekitRedhat Enterprise LinuxFedoraproject Fedora | 3/1/2024 | 17/6/2026 | A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored… | |
| Modificada | Media (4.8) | 0.45% | — | LibsshFedoraproject FedoraRedhat Enterprise Linux | 3/1/2024 | 17/6/2026 | A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter. | |
| Modificada | Media (5.3) | 0.33% | — | QemuRedhat Enterprise LinuxFedoraproject Fedora | 2/1/2024 | 17/6/2026 | A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables… | |
| Modificada | Alta (7.3) | 1.2% | — | SqliteFedoraproject Fedora | 29/12/2023 | 17/6/2026 | A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this… | |
| Modificada | Crítica (9.8) | 1.2% | — | AomediaFedoraproject Fedora | 27/12/2023 | 23/6/2026 | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). | |
| Analizada | Alta (7.8) | 19% | ⚠ Explotación activa💥 Exploit | Jmcnamara Spreadsheet\Debian LinuxFedoraproject Fedora | 24/12/2023 | 17/6/2026 | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings… | |
| Modificada | Alta (7) | 0.66% | — | Openbsd OpensshFedoraproject FedoraRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the… | |
| Modificada | Media (5.3) | 1.1% | — | EximFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 24/12/2023 | 17/6/2026 | Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other… | |
| Modificada | Media (5.3) | 2.6% | 💥 PoC | PostfixFedoraproject FedoraRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed… | |
| Analizada | Alta (8.8) | 6.7% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxFedoraproject Fedora | 21/12/2023 | 17/6/2026 | Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7) | 0.73% | 💥 PoC | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 21/12/2023 | 6/8/2026 | A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This… | |
| Modificada | Media (5.5) | 0.33% | — | Broadcom TcpreplayFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 21/12/2023 | 17/6/2026 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service… | |
| Modificada | Media (5.5) | 0.32% | — | Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 21/12/2023 | 17/6/2026 | An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of… | |
| Modificada | Media (5.3) | 1.4% | — | LibsshFedoraproject FedoraRedhat Enterprise Linux | 19/12/2023 | 17/6/2026 | A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as… | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (7.8) | 0.81% | — | PerlFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1 | 18/12/2023 | 17/6/2026 | A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer. | |
| Modificada | Alta (8.8) | 44% | 💥 PoC | Google ChromeFedoraproject FedoraMicrosoft Edge Chromium | 14/12/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.8) | 0.54% | — | Redhat AnsibleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Ansible Automation Platform+2 | 12/12/2023 | 17/6/2026 | A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data. | |
| Modificada | Media (5.3) | 1.1% | — | Haxx CurlFedoraproject Fedora | 12/12/2023 | 17/6/2026 | When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use. | |
| Modificada | Media (5.5) | 0.31% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 11/12/2023 | 17/6/2026 | A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service. | |
| Modificada | Alta (8.8) | 0.77% | — | LibreofficeFedoraproject FedoraDebian Linux | 11/12/2023 | 17/6/2026 | Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user. |