Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

6914 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.35%—C-aresFedoraproject Fedora23/2/202417/6/2026
c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL`…
ModificadaMedia (6.5)1.2%💥 PoCDebian LinuxFedoraproject FedoraRedhat Enterprise LinuxW1.fi WPA Supplicant22/2/202417/6/2026
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The…
AnalizadaAlta (7.5)1.0%—OpenvswitchFedoraproject Fedora22/2/202417/6/2026
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
ModificadaAlta (7.5)1.3%—WiresharkFedoraproject Fedora21/2/202417/6/2026
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
ModificadaAlta (7.5)1.3%—Fedoraproject FedoraWireshark21/2/202417/6/2026
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
AnalizadaMedia (4.3)0.85%—Apple SafariApple Ipad OSApple Iphone OSApple Macos+321/2/202417/6/2026
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
AnalizadaMedia (5.4)19%—Google ChromeFedoraproject Fedora21/2/202417/6/2026
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
ModificadaAlta (8.8)11%—Google ChromeFedoraproject Fedora21/2/202417/6/2026
Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.79%—Google ChromeFedoraproject Fedora21/2/202417/6/2026
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaAlta (8.8)0.80%—Google ChromeFedoraproject Fedora21/2/202417/6/2026
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
AnalizadaMedia (5.4)0.89%—Google ChromeFedoraproject Fedora21/2/202417/6/2026
Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaAlta (8.8)9.1%—Google ChromeFedoraproject Fedora21/2/202417/6/2026
Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.96%—Google ChromeFedoraproject Fedora21/2/202417/6/2026
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.8)1.7%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.8%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger…
ModificadaCrítica (9.8)1.7%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.6%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.8%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger…
ModificadaCrítica (9.8)1.8%—Libbiosig Project LibbiosigFedoraproject Fedora20/2/202417/6/2026
A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaAlta (7.5)1.2%—Agronholm Cbor2Fedoraproject Fedora19/2/202417/6/2026
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this…
AnalizadaMedia (5.3)0.60%—MoodleFedoraproject Fedora19/2/202417/6/2026
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
AnalizadaAlta (8.8)0.50%—MoodleFedoraproject Fedora19/2/202417/6/2026
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
AnalizadaMedia (5.3)0.58%—MoodleFedoraproject Fedora19/2/202417/6/2026
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.