Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

5178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.61%—Innovadeluxe Manufacturer OR Supplier Alphabetical Search9/2/202417/6/2026
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink,…
ModificadaMedia (5.5)0.28%—Canonical Ubuntu Pipewire-pulse24/1/202417/6/2026
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
ModificadaAlta (7.4)0.32%—Oracle Financial Services Analytical Applications Infrastructure16/1/202417/6/2026
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows low privileged attacker with…
ModificadaMedia (5.5)0.27%—Linux KernelCanonical Ubuntu Linux8/1/202417/6/2026
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067.
ModificadaAlta (7.8)0.28%—Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux8/1/202417/6/2026
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
ModificadaAlta (7)0.38%💥 PoCCanonical SnapdCanonical Ubuntu Linux8/1/202417/6/2026
Race condition in snap-confine's must_mkdir_and_open_with_perms()
ModificadaAlta (7)1.4%💥 PoCLinux KernelCanonical Ubuntu Linux8/1/202417/6/2026
io_uring UAF, Unix SCM garbage collection
ModificadaAlta (7.8)5.9%💥 PoCLinux KernelCanonical Ubuntu Linux8/1/202417/6/2026
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.
AnalizadaAlta (7.8)10%⚠ Explotación activa💥 PoCLinux KernelCanonical Ubuntu Linux8/1/202420/8/2026
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
ModificadaAlta (7.8)1.3%—Linux KernelCanonical Ubuntu Linux8/1/202417/6/2026
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
ModificadaMedia (6.4)0.24%—Canonical Ubuntu Linux12/12/202317/6/2026
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.
ModificadaAlta (7.3)0.48%—SAP Graphical User Interface12/12/202317/6/2026
SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to create Layout…
ModificadaMedia (6.3)7.9%💥 PoCGoogle AndroidCanonical Ubuntu LinuxApple Iphone OSApple Macos+38/12/202317/6/2026
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example…
ModificadaAlta (7.8)0.27%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+623/11/202317/6/2026
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.27%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+623/11/202317/6/2026
A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
ModificadaCrítica (9.8)1.1%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+623/11/202317/6/2026
A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
ModificadaCrítica (9.8)1.1%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+623/11/202317/6/2026
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaCrítica (9.8)1.1%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+623/11/202317/6/2026
A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaCrítica (9.8)1.1%—Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+623/11/202317/6/2026
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaMedia (5.4)0.38%—Bmicalculator BMI Calculator22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Waterloo Plugins BMI Calculator Plugin plugin <= 1.0.3 versions.
ModificadaAlta (8.8)0.28%—Gopiplus Vertical Scroll Recent Registered User18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy Vertical scroll recent.This issue affects Vertical scroll recent post: from n/a through 14.0.
ModificadaAlta (7.5)0.60%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
ModificadaAlta (7.5)0.70%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
ModificadaAlta (7.5)0.72%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
ModificadaMedia (6.5)0.79%—Gopiplus Vertical Marquee Plugin31/10/202317/6/2026
The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with…