Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)16%—Blackmagicdesign Davinci Resolve22/12/202117/6/2026
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate the size of a heap buffer. Due to an integer overflow with regards…
ModificadaAlta (7.5)1.4%—NIC Knot Resolver25/8/202117/6/2026
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
ModificadaCrítica (9.8)2.9%—Pac-resolver Project Pac-resolver24/8/202117/6/2026
This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.
ModificadaAlta (7.5)1.2%—NIC Knot Resolver30/3/202117/6/2026
A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.
ModificadaAlta (7.5)2.6%—NIC Knot Resolver19/5/202017/6/2026
Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
ModificadaMedia (5.9)0.86%—Postfix-mta-sts-resolver Project Postfix-mta-sts-resolver22/1/202017/6/2026
In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.
ModificadaAlta (7.5)2.1%—NIC Knot ResolverDebian Linux16/12/201917/6/2026
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed…
ModificadaMedia (5.9)3.5%—ISC BindNlnetlabs NSDNIC Knot ResolverRedhat Enterprise Linux5/11/201916/6/2026
Cache Poisoning issue exists in DNS Response Rate Limiting.
ModificadaAlta (7.5)1.9%—NIC Knot ResolverFedoraproject Fedora16/7/201917/6/2026
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.
ModificadaAlta (7.5)2.0%—NIC Knot ResolverFedoraproject Fedora16/7/201917/6/2026
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-existence answer. NXDOMAIN answer would get passed through to the client even if its DNSSEC validation failed, instead of sending a SERVFAIL…
ModificadaMedia (6.8)3.2%—NIC Knot Resolver2/8/201817/6/2026
Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.
ModificadaAlta (7.5)2.4%—Resolve-path Project Resolve-path7/6/201817/6/2026
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path.
ModificadaBaja (3.7)1.1%—NIC Knot Resolver22/1/201817/6/2026
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
ModificadaAlta (8.8)5.6%—Resolver Perspective11/12/201717/6/2026
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.
ModificadaMedia (5)2.7%—Webresolve31/12/200216/6/2026
Buffer overflow in Webresolve 0.1.0 and earlier allows remote attackers to execute arbitrary code by connecting to the server from an IP address that resolves to a long hostname.