Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.35%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.37%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
AnalizadaAlta (7.8)3.1%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
ModificadaCrítica (9.8)8.0%💥 PoCImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
AnalizadaMedia (5.5)0.95%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+130/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
ModificadaAlta (7.3)1.1%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora2/5/202317/6/2026
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
ModificadaMedia (5.3)6.6%💥 ExploitMoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora2/5/202317/6/2026
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
ModificadaMedia (5.5)0.59%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora12/4/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (6.5)1.8%—HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+523/3/202317/6/2026
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
ModificadaMedia (5.5)0.86%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux23/3/202317/6/2026
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When…
ModificadaCrítica (9.8)2.1%—Rxvt-unicode Project Rxvt-unicodeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/12/202217/6/2026
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
ModificadaMedia (6.5)0.29%—QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux29/11/202217/6/2026
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash…
ModificadaCrítica (9.1)1.4%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora25/11/202217/6/2026
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP…
ModificadaMedia (4.3)0.66%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora30/9/202217/6/2026
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
ModificadaCrítica (9.8)1.0%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora30/9/202217/6/2026
A limited SQL injection risk was identified in the "browse list of users" site administration page.
ModificadaAlta (7.1)0.64%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora30/9/202217/6/2026
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
ModificadaMedia (5.5)0.49%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora19/9/202217/6/2026
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
ModificadaAlta (7.8)0.46%—LibmodbusFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux29/8/202217/6/2026
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
ModificadaBaja (3.2)0.39%—QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Openstack Platform+117/8/202217/6/2026
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
ModificadaMedia (5.5)0.34%—Fedoraproject Extra Packages FOR Enterprise LinuxImagemagickFedoraproject Fedora10/8/202217/6/2026
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.
ModificadaAlta (8.8)1.1%—Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora28/7/202217/6/2026
Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.
ModificadaAlta (8.8)1.4%—Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora28/7/202217/6/2026
Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
AnalizadaAlta (8.8)70%⚠ Explotación activaGoogle ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraWebkitgtk+828/7/20224/8/2026
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)0.82%—Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora28/7/202217/6/2026
Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.
ModificadaAlta (8.8)1.0%—Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora28/7/202217/6/2026
Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Orbitaley — Vulnerabilidades