Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.45% | — | GitoxideAI | 23/5/2024 | 17/6/2026 | gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary… | |
| Aplazada | Alta (8.8) | 0.82% | — | GitoxideAI | 23/5/2024 | 17/6/2026 | gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality,… | |
| Aplazada | Media (6.4) | 0.51% | — | Gitoxide Gix-transportAI | 26/4/2024 | 17/6/2026 | gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by… | |
| Modificada | Crítica (9.8) | 1.5% | — | Sodiumoxide Project Sodiumoxide | 31/12/2020 | 17/6/2026 | An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itself and thus has degenerate security properties. | |
| Modificada | Alta (7.5) | 0.66% | — | Oxide Project Oxide | 22/4/2019 | 17/6/2026 | A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3. | |
| Modificada | Media (6.5) | 1.3% | — | Sodiumoxide Project Sodiumoxide | 17/11/2017 | 17/6/2026 | sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys | |
| Modificada | Alta (8.8) | 2.6% | — | Canonical Ubuntu LinuxOxide Project Oxide | 25/7/2017 | 17/6/2026 | The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website. | |
| Modificada | Crítica (9.8) | 3.0% | — | Canonical Ubuntu LinuxOxide Project Oxide | 13/5/2016 | 17/6/2026 | Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests. | |
| Modificada | Media (6.8) | 2.0% | — | Canonical Ubuntu LinuxOxide Project Oxide | 29/4/2015 | 17/6/2026 | Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage. | |
| Modificada | Alta (7.5) | 3.0% | — | Canonical Ubuntu LinuxOxide Project Oxide | 8/4/2015 | 17/6/2026 | Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists. | |
| Modificada | Media (5) | 2.9% | — | Monoxide0184 Oxide Webserver | 8/12/2011 | 16/6/2026 | Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request. |