Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | LibreofficeFedoraproject FedoraDebian Linux | 11/12/2023 | 17/6/2026 | Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer… | |
| Analizada | Media (5.5) | 0.32% | — | Fedoraproject FedoraLinux KernelRedhat Enterprise Linux | 8/12/2023 | 17/6/2026 | A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service. | |
| Modificada | Media (6.3) | 7.9% | 💥 PoC | Google AndroidCanonical Ubuntu LinuxApple Iphone OSApple Macos+3 | 8/12/2023 | 17/6/2026 | Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example… | |
| Modificada | Media (6.5) | 1.7% | — | Haxx CurlFedoraproject Fedora | 7/12/2023 | 17/6/2026 | This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in… | |
| Modificada | Media (6.5) | 1.3% | — | Debian LinuxFedoraproject FedoraGoogle Chrome | 6/12/2023 | 17/6/2026 | Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.86% | — | Debian LinuxFedoraproject FedoraGoogle Chrome | 6/12/2023 | 17/6/2026 | Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Alta (8.8) | 1.0% | — | Debian LinuxFedoraproject FedoraGoogle Chrome | 6/12/2023 | 17/6/2026 | Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 1.0% | — | Debian LinuxFedoraproject FedoraGoogle Chrome | 6/12/2023 | 17/6/2026 | Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeDebian LinuxFedoraproject Fedora | 6/12/2023 | 17/6/2026 | Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 9.3% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/11/2023 | 17/6/2026 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before… | |
| Analizada | Media (6.5) | 18% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 30/11/2023 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS… | |
| Modificada | Alta (8.8) | 0.93% | — | Google ChromeDebian LinuxFedoraproject Fedora | 29/11/2023 | 17/6/2026 | Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.3% | 💥 PoC | Google ChromeDebian LinuxFedoraproject Fedora | 29/11/2023 | 17/6/2026 | Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 29/11/2023 | 17/6/2026 | Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 29/11/2023 | 17/6/2026 | Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeDebian LinuxFedoraproject Fedora | 29/11/2023 | 17/6/2026 | Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 16% | ⚠ Explotación activa | Google ChromeDebian LinuxFedoraproject FedoraMicrosoft Edge Chromium | 29/11/2023 | 17/6/2026 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) | |
| Analizada | Media (5.9) | 1.3% | — | Debian LinuxGnutlsRedhat LinuxFedoraproject Fedora | 28/11/2023 | 17/6/2026 | A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. | |
| Modificada | Media (6.5) | 1.8% | — | LibtiffFedoraproject Fedora | 24/11/2023 | 17/6/2026 | An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB. | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelFedoraproject Fedora | 23/11/2023 | 17/6/2026 | A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system. | |
| Analizada | Media (4.7) | 0.54% | — | Fedoraproject FedoraNetapp HCI Compute NodeNeovimVIM | 22/11/2023 | 17/9/2026 | Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed… | |
| Modificada | Media (6.7) | 0.29% | — | Linux KernelFedoraproject Fedora | 21/11/2023 | 17/6/2026 | A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory… | |
| Modificada | Media (5.5) | 0.48% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 19/11/2023 | 17/6/2026 | A heap use-after-free flaw was found in coders/bmp.c in ImageMagick. | |
| Modificada | Media (4.3) | 0.76% | — | VIMFedoraproject Fedora | 16/11/2023 | 23/6/2026 | Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a very large value, it may be possible to overflow the size of integer. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been… | |
| Modificada | Media (4.3) | 0.69% | — | VIMFedoraproject Fedora | 16/11/2023 | 23/6/2026 | Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values larger than MAX_INT. Impact is low, user interaction is required and a crash may not even happen in all situations. This vulnerability has been addressed in commit `73b2d379` which has been included… |