Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.61% | — | Innovadeluxe Manufacturer OR Supplier Alphabetical Search | 9/2/2024 | 17/6/2026 | SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink,… | |
| Modificada | Media (5.5) | 0.28% | — | Canonical Ubuntu Pipewire-pulse | 24/1/2024 | 17/6/2026 | Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set. | |
| Modificada | Alta (7.4) | 0.32% | — | Oracle Financial Services Analytical Applications Infrastructure | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Media (5.5) | 0.27% | — | Linux KernelCanonical Ubuntu Linux | 8/1/2024 | 17/6/2026 | The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067. | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux | 8/1/2024 | 17/6/2026 | It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code. | |
| Modificada | Alta (7) | 0.38% | 💥 PoC | Canonical SnapdCanonical Ubuntu Linux | 8/1/2024 | 17/6/2026 | Race condition in snap-confine's must_mkdir_and_open_with_perms() | |
| Modificada | Alta (7) | 1.4% | 💥 PoC | Linux KernelCanonical Ubuntu Linux | 8/1/2024 | 17/6/2026 | io_uring UAF, Unix SCM garbage collection | |
| Modificada | Alta (7.8) | 5.9% | 💥 PoC | Linux KernelCanonical Ubuntu Linux | 8/1/2024 | 17/6/2026 | It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0. | |
| Analizada | Alta (7.8) | 10% | ⚠ Explotación activa💥 PoC | Linux KernelCanonical Ubuntu Linux | 8/1/2024 | 20/8/2026 | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. | |
| Modificada | Alta (7.8) | 1.3% | — | Linux KernelCanonical Ubuntu Linux | 8/1/2024 | 17/6/2026 | It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free. | |
| Modificada | Media (6.4) | 0.24% | — | Canonical Ubuntu Linux | 12/12/2023 | 17/6/2026 | A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password. | |
| Modificada | Alta (7.3) | 0.48% | — | SAP Graphical User Interface | 12/12/2023 | 17/6/2026 | SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to create Layout… | |
| Modificada | Media (6.3) | 7.9% | 💥 PoC | Google AndroidCanonical Ubuntu LinuxApple Iphone OSApple Macos+3 | 8/12/2023 | 17/6/2026 | Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example… | |
| Modificada | Alta (7.8) | 0.27% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 23/11/2023 | 17/6/2026 | A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.27% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 23/11/2023 | 17/6/2026 | A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. | |
| Modificada | Crítica (9.8) | 1.1% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 23/11/2023 | 17/6/2026 | A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. | |
| Modificada | Crítica (9.8) | 1.1% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 23/11/2023 | 17/6/2026 | A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Crítica (9.8) | 1.1% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 23/11/2023 | 17/6/2026 | A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Crítica (9.8) | 1.1% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+6 | 23/11/2023 | 17/6/2026 | A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Media (5.4) | 0.38% | — | Bmicalculator BMI Calculator | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Waterloo Plugins BMI Calculator Plugin plugin <= 1.0.3 versions. | |
| Modificada | Alta (8.8) | 0.28% | — | Gopiplus Vertical Scroll Recent Registered User | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy Vertical scroll recent.This issue affects Vertical scroll recent post: from n/a through 14.0. | |
| Modificada | Alta (7.5) | 0.60% | — | Bestpractical Request Tracker | 3/11/2023 | 17/6/2026 | Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder. | |
| Modificada | Alta (7.5) | 0.70% | — | Bestpractical Request Tracker | 3/11/2023 | 17/6/2026 | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls. | |
| Modificada | Alta (7.5) | 0.72% | — | Bestpractical Request Tracker | 3/11/2023 | 17/6/2026 | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call. | |
| Modificada | Media (6.5) | 0.79% | — | Gopiplus Vertical Marquee Plugin | 31/10/2023 | 17/6/2026 | The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with… |