Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 491 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.33%—GNU Binutils22/8/202317/6/2026
An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.
ModificadaAlta (8.8)0.75%—GNU Binutils22/8/202317/6/2026
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
ModificadaMedia (5.5)0.30%—GNU Binutils22/8/202317/6/2026
A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.
ModificadaMedia (5.5)0.44%—GNU Indent14/8/202317/6/2026
GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
ModificadaAlta (7.8)0.41%—GNU Inetutils14/8/202317/6/2026
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the…
ModificadaAlta (7.8)0.18%—ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+727/7/202317/6/2026
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.
ModificadaMedia (5.5)0.24%—GNU GDB25/7/202317/6/2026
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c.
ModificadaMedia (5.5)0.26%—GNU GDB25/7/202317/6/2026
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c.
ModificadaMedia (5.5)0.32%—GNU GDB25/7/202317/6/2026
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c.
ModificadaAlta (7.8)0.29%—GNU Grub220/7/202317/6/2026
There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than once a use-after-free vulnerability is triggered. If an attacker can…
ModificadaAlta (7.8)0.31%—GNU Grub220/7/202317/6/2026
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
ModificadaAlta (7)1.1%—GNU Grub2Netapp Active IQ Unified Manager20/7/202317/6/2026
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker…
ModificadaAlta (8.1)1.3%—GNU Grub220/7/202317/6/2026
Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation.…
ModificadaMedia (6.5)0.75%—GNU Binutils18/7/202317/6/2026
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.
ModificadaCrítica (9.8)1.0%—Gnuplot5/7/202317/6/2026
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
ModificadaMedia (5.5)0.32%—GNU Glibc25/6/202317/6/2026
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also,…
AnalizadaAlta (8.8)0.92%—GNU Libredwg23/6/202317/6/2026
LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
ModificadaAlta (8.8)0.70%—GNU Libredwg23/6/202317/6/2026
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
ModificadaAlta (8.8)0.92%—GNU Libredwg23/6/202317/6/2026
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
AnalizadaAlta (8.8)0.92%—GNU Libredwg23/6/202317/6/2026
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.
ModificadaCrítica (9.8)94%💥 ExploitMagnussolution Magnusbilling23/6/202317/6/2026
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
ModificadaMedia (4.6)0.70%—Xootix Login/signup Popup7/6/202317/6/2026
The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can…
ModificadaAlta (7.5)1.2%—GNU Cflow18/5/202317/6/2026
A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of the file parser.c. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-229373 was assigned to…
ModificadaAlta (7.8)0.46%—GNU EmacsRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+117/5/202317/6/2026
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat…
ModificadaMedia (6.5)0.90%—GNU Binutils17/5/202317/6/2026
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.