Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.61% | — | Perl Crypt Openssl Pkcs12AI | 9/8/2026 | 26/8/2026 | Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length, char)`. A zero length attribute makes… | |
| Aplazada | Baja (2.5) | 0.14% | — | Perl File Rotate SimpleAI | 7/8/2026 | 26/8/2026 | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target),… | |
| Aplazada | Alta (7.5) | 0.51% | — | Perl ImagerAI | 7/8/2026 | 26/8/2026 | Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and… | |
| Aplazada | Media (6.5) | 0.34% | — | Paperless-ngxAI | 5/8/2026 | 26/8/2026 | Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap_security in the same… | |
| Aplazada | Alta (7.5) | 0.63% | — | Perl Date ManipAI | 30/7/2026 | 2/9/2026 | Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached… | |
| Aplazada | Baja (3.8) | 0.14% | — | Perl Data Spatialhash SharedAI | 21/7/2026 | 23/7/2026 | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).… | |
| Aplazada | Baja (3.8) | 0.14% | — | Perl Data Hashmap SharedAI | 21/7/2026 | 23/7/2026 | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h with open(path, O_RDWR | O_CREAT | O_CLOEXEC, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644… | |
| Aplazada | Baja (3.8) | 0.14% | — | Perl Data Reqrep SharedAI | 21/7/2026 | 23/7/2026 | Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h with open(path, O_RDWR | O_CREAT, 0666), for both the request-reply and the integer-variant segments. The mode is 0666, so under the default umask… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Perl Data Disjointset SharedAI | 21/7/2026 | 23/7/2026 | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. dsu_find… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Perl Data Intern SharedAI | 21/7/2026 | 22/7/2026 | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough about the header and layout (magic, version, section offsets, total_size, count and arena_used) but does not validate… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Perl Data Ringbuffer SharedAI | 21/7/2026 | 22/7/2026 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination size. ring_read_seq… | |
| Analizada | Crítica (9.8) | 0.52% | — | Proxmox Libpve-storage-perl | 17/7/2026 | 11/8/2026 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | |
| Aplazada | Alta (7.8) | 0.17% | — | Yaml SyckAIPerl Yaml SyckAI | 16/7/2026 | 17/7/2026 | YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor. In the bundled libsyck an anchor name allocated by syck_strndup is stored both as node->anchor, freed when the node is freed, and as the key in the parser's anchors table.… | |
| Aplazada | Media (6.2) | 0.13% | — | Yaml SyckAIPerlAI | 16/7/2026 | 17/7/2026 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node stored under that name with syck_free_node.… | |
| Aplazada | Crítica (9.8) | 0.70% | — | EpegAIPerl Image EpegAI | 16/7/2026 | 17/7/2026 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project. | |
| Aplazada | Crítica (9.1) | 0.65% | — | Perl DBIAI | 14/7/2026 | 15/7/2026 | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to… | |
| Aplazada | Alta (7.7) | 0.16% | — | Perl DBD FileAI | 14/7/2026 | 15/7/2026 | DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Perl DBIAIPerl DBI SQL NanoAI | 14/7/2026 | 14/7/2026 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was… | |
| Modificada | Alta (8.4) | 0.21% | — | Perl | 13/7/2026 | 8/9/2026 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat… | |
| Modificada | Crítica (9.1) | 0.43% | — | Perl | 13/7/2026 | 8/9/2026 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the… | |
| Analizada | Crítica (9.1) | 0.39% | — | Perl DBI | 7/7/2026 | 10/7/2026 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a… | |
| Analizada | Crítica (9.8) | 0.41% | — | Perl DBI | 7/7/2026 | 10/7/2026 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders. | |
| Modificada | Alta (8.8) | 0.50% | — | Perl DBI | 7/7/2026 | 31/8/2026 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any… | |
| Aplazada | Alta (7.1) | 0.25% | — | Perl Http TinyAI | 7/7/2026 | 8/7/2026 | HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the… | |
| Aplazada | Crítica (9.8) | 0.78% | — | Perl Module LoadAI | 7/7/2026 | 7/7/2026 | Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to specify arbitrary module paths. Attackers able to influence module names passed to load could use that bug to execute arbitrary code. |