Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.55% | — | Debian LinuxGoogle ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.48% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.45% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.39% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium) | |
| Modificada | Alta (7.5) | 0.49% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (7.5) | 0.98% | — | Linux KernelFedoraproject Fedora | 23/1/2024 | 17/6/2026 | An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol. | |
| Modificada | Media (6.8) | 0.29% | — | Notaryproject Notation-go | 19/1/2024 | 17/6/2026 | The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts. An external actor with control of a compromised container registry can provide outdated versions of OCI artifacts, such… | |
| Modificada | Media (6.5) | 0.67% | — | JupyterlabJupyter NotebookFedoraproject Fedora | 19/1/2024 | 17/6/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab… | |
| Modificada | Media (6.1) | 0.57% | — | JupyterlabJupyter NotebookFedoraproject Fedora | 19/1/2024 | 17/6/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has… | |
| Modificada | Alta (7.5) | 0.98% | — | Easy File Sharing FTP Server Project Easy File Sharing FTP Server | 19/1/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in EFS Easy File Sharing FTP 3.6. This affects an unknown part of the component Login. The manipulation of the argument password leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 1.0% | — | Jester Project Jester | 19/1/2024 | 17/6/2026 | An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request. | |
| Modificada | Media (5.3) | 0.97% | — | Easy Chat Server Project Easy Chat Server | 18/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of the component HTTP GET Request Handler. The manipulation of the argument USERNAME leads to denial of service. The attack may be launched remotely. The exploit has… | |
| Modificada | Alta (7.5) | 1.3% | — | Easy File Sharing FTP Server Project Easy File Sharing FTP Server | 18/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (6.6) | 0.24% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 18/1/2024 | 17/6/2026 | A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of u32, so each element only has space for 4 bytes. That means every… | |
| Modificada | Alta (7.8) | 0.36% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context. | |
| Modificada | Media (5.5) | 0.32% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX… | |
| Modificada | Crítica (9.8) | 2.1% | — | X.org X ServerX.org XwaylandFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 18/1/2024 | 17/6/2026 | A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow… | |
| Analizada | Alta (8.8) | 3.8% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraCouchbase Server | 16/1/2024 | 17/6/2026 | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeFedoraproject Fedora | 16/1/2024 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 22% | — | Google ChromeFedoraproject Fedora | 16/1/2024 | 17/6/2026 | Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.8) | 1.6% | — | Rpm-software-management MockFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in… | |
| Modificada | Alta (7.5) | 1.4% | — | GnutlsFedoraproject FedoraNetapp Active IQ Unified ManagerDebian Linux | 16/1/2024 | 17/6/2026 | A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack. | |
| Modificada | Media (5.5) | 0.38% | — | SqliteRedhat Enterprise LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | GnutlsFedoraproject FedoraRedhat Enterprise Linux | 16/1/2024 | 17/6/2026 | A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading… | |
| Modificada | Alta (8.8) | 3.5% | 💥 Exploit | Easyftp Server Project Easyftp Server | 16/1/2024 | 16/6/2026 | A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of… |