Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.35% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.37% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Analizada | Alta (7.8) | 3.1% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding. | |
| Modificada | Crítica (9.8) | 8.0% | 💥 PoC | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. | |
| Analizada | Media (5.5) | 0.95% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+1 | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). | |
| Modificada | Alta (7.3) | 1.1% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 2/5/2023 | 17/6/2026 | The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database. | |
| Modificada | Media (5.3) | 6.6% | 💥 Exploit | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 2/5/2023 | 17/6/2026 | The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system. | |
| Modificada | Media (5.5) | 0.59% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 12/4/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (6.5) | 1.8% | — | HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+5 | 23/3/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability. | |
| Modificada | Media (5.5) | 0.86% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 23/3/2023 | 17/6/2026 | A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When… | |
| Modificada | Crítica (9.8) | 2.1% | — | Rxvt-unicode Project Rxvt-unicodeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/12/2022 | 17/6/2026 | The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set. | |
| Modificada | Media (6.5) | 0.29% | — | QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 29/11/2022 | 17/6/2026 | An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash… | |
| Modificada | Crítica (9.1) | 1.4% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 25/11/2022 | 17/6/2026 | A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP… | |
| Modificada | Media (4.3) | 0.66% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | |
| Modificada | Crítica (9.8) | 1.0% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | A limited SQL injection risk was identified in the "browse list of users" site administration page. | |
| Modificada | Alta (7.1) | 0.64% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. | |
| Modificada | Media (5.5) | 0.49% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 19/9/2022 | 17/6/2026 | A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. | |
| Modificada | Alta (7.8) | 0.46% | — | LibmodbusFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 29/8/2022 | 17/6/2026 | A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. | |
| Modificada | Baja (3.2) | 0.39% | — | QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Openstack Platform+1 | 17/8/2022 | 17/6/2026 | An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.34% | — | Fedoraproject Extra Packages FOR Enterprise LinuxImagemagickFedoraproject Fedora | 10/8/2022 | 17/6/2026 | In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30. | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Analizada | Alta (8.8) | 70% | ⚠ Explotación activa | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraWebkitgtk+8 | 28/7/2022 | 4/8/2026 | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 0.82% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction. | |
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |