Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.53% | — | MoodleFedoraproject Fedora | 19/2/2024 | 17/6/2026 | Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers. | |
| Analizada | Media (5.3) | 0.59% | — | MoodleFedoraproject Fedora | 19/2/2024 | 17/6/2026 | The URL parameters accepted by forum search were not limited to the allowed parameters. | |
| Analizada | Alta (7.5) | 0.94% | — | MoodleFedoraproject Fedora | 19/2/2024 | 17/6/2026 | Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. | |
| Modificada | Crítica (9.8) | 4.8% | — | Postgresql Jdbc DriverFedoraproject Fedora | 19/2/2024 | 17/6/2026 | pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the… | |
| Modificada | Alta (8.8) | 1.8% | — | Videolan Dav1dApple SafariApple IpadosApple Iphone OS+3 | 19/2/2024 | 17/6/2026 | An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d. | |
| Modificada | Alta (7.3) | 0.32% | — | Fedoraproject UnboundRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+15 | 15/2/2024 | 6/8/2026 | A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to… | |
| Analizada | Alta (7.5) | 74% | 💥 PoC | Netapp HCI Baseboard Management ControllerNetapp Active IQ Unified ManagerNetapp Bootstrap OSPowerdns Recursor+4 | 14/2/2024 | 17/6/2026 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an… | |
| Modificada | Alta (7.5) | 100% | 💥 PoC | Redhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+9 | 14/2/2024 | 17/6/2026 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the… | |
| Modificada | Alta (7.5) | 1.3% | — | MOD Auth OpenidcDebian LinuxFedoraproject Fedora | 13/2/2024 | 17/6/2026 | mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of… | |
| Modificada | Alta (7.5) | 1.2% | — | Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and… | |
| Modificada | Alta (7.5) | 1.2% | — | Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: | |
| Modificada | Alta (7.5) | 1.3% | — | Netapp OntapFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative… | |
| Modificada | Baja (3.4) | 0.42% | — | Opensc Project OpenscFedoraproject FedoraRedhat Enterprise Linux | 12/2/2024 | 17/6/2026 | The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present… | |
| Modificada | Media (5.3) | 0.88% | — | Latchset JwcryptoFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux FOR ARM 64+2 | 12/2/2024 | 17/6/2026 | A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack. | |
| Modificada | Media (5.5) | 0.31% | — | Redhat 389 Directory ServerRedhat Directory ServerFedoraproject FedoraRedhat Enterprise Linux+9 | 12/2/2024 | 17/6/2026 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelFedoraproject Fedora | 12/2/2024 | 17/6/2026 | dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and crash, because of a missing check for struct dm_ioctl.target_count. | |
| Modificada | Media (5.5) | 0.27% | — | Debian LinuxFedoraproject FedoraRedhat Enterprise LinuxLinux Kernel | 11/2/2024 | 17/6/2026 | A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a… | |
| Modificada | Media (6.1) | 0.41% | — | Glewlwyd SSO Server Project Glewlwyd SSO Server | 11/2/2024 | 17/6/2026 | Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri. | |
| Modificada | Alta (7.8) | 1.2% | — | X.org X ServerX.org XwaylandFedoraproject FedoraRedhat Enterprise Linux+4 | 9/2/2024 | 17/6/2026 | An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution… | |
| Modificada | Media (4.7) | 0.23% | — | Linux KernelFedoraproject Fedora | 8/2/2024 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time with a fail in the mas_prev_slot function. This issue could allow a local user to crash the system. | |
| Modificada | Alta (7.5) | 33% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora | 7/2/2024 | 17/6/2026 | A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker… | |
| Modificada | Crítica (9.8) | 0.80% | — | Bookingcalendar Project Bookingcalendar | 7/2/2024 | 17/6/2026 | SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Google ChromeFedoraproject Fedora | 7/2/2024 | 17/6/2026 | Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.8) | 22% | — | Google ChromeFedoraproject Fedora | 7/2/2024 | 17/6/2026 | Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Baja (3.3) | 0.27% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 6/2/2024 | 17/6/2026 | A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may… |