Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.45%—GitoxideAI23/5/202417/6/2026
gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary…
AplazadaAlta (8.8)0.82%—GitoxideAI23/5/202417/6/2026
gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality,…
AplazadaMedia (6.4)0.51%—Gitoxide Gix-transportAI26/4/202417/6/2026
gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by…
ModificadaCrítica (9.8)1.5%—Sodiumoxide Project Sodiumoxide31/12/202017/6/2026
An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itself and thus has degenerate security properties.
ModificadaAlta (7.5)0.66%—Oxide Project Oxide22/4/201917/6/2026
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
ModificadaMedia (6.5)1.3%—Sodiumoxide Project Sodiumoxide17/11/201717/6/2026
sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys
ModificadaAlta (8.8)2.6%—Canonical Ubuntu LinuxOxide Project Oxide25/7/201717/6/2026
The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.
ModificadaCrítica (9.8)3.0%—Canonical Ubuntu LinuxOxide Project Oxide13/5/201617/6/2026
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests.
ModificadaMedia (6.8)2.0%—Canonical Ubuntu LinuxOxide Project Oxide29/4/201517/6/2026
Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
ModificadaAlta (7.5)3.0%—Canonical Ubuntu LinuxOxide Project Oxide8/4/201517/6/2026
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.
ModificadaMedia (5)2.9%—Monoxide0184 Oxide Webserver8/12/201116/6/2026
Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.