Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

84 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—WP Slacksync12/11/201917/6/2026
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
ModificadaAlta (7.1)1.1%—Jenkins Slack Notification28/3/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaAlta (7.5)1.4%—Jenkins Slack Notification28/3/201917/6/2026
A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaCrítica (9.8)1.7%—Slack Archivebot Project Slack Archivebot20/9/201817/6/2026
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().
ModificadaAlta (7.8)0.60%—OpenvpnSlackware Linux1/5/201817/6/2026
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including…
ModificadaAlta (7.5)8.5%—NTPSynology Router ManagerSynology SkynasSynology Virtual Diskstation Manager+66/3/201817/6/2026
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp.…
ModificadaCrítica (9.8)7.0%—HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+159/6/201617/6/2026
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
ModificadaAlta (7.8)34%—ISC BindSuse Linux Enterprise Software Development KITNovell Suse LinuxISC Dnsco Bind+829/7/201316/6/2026
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA…
ModificadaCrítica (9.8)70%💥 ExploitTcpdumpCanonical Ubuntu LinuxDebian LinuxSlackware+316/7/200716/6/2026
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
ModificadaMedia (6.4)0.86%—Slackroll29/6/200716/6/2026
SlackRoll before 8 accepts gpg exit codes other than 0 and 1 as evidence of a valid signature, which allows remote Slackware mirror sites or man-in-the-middle attackers to cause a denial of service (data inconsistency) or possibly install Trojan horse packages via malformed gpg signatures.
ModificadaBaja (3.8)1.5%—Mandrakesoft Mandrake Multi Network FirewallX.org LibxfontRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+86/4/200716/6/2026
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
ModificadaBaja (1.9)0.46%—Slackware Linux7/2/200716/6/2026
xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory. NOTE: it could be argued…
ModificadaAlta (10)5.9%—GNU Privacy GuardGpg4winRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+57/12/200616/6/2026
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
ModificadaMedia (5)3.4%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
ModificadaMedia (5)2.3%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
ModificadaAlta (10)3.8%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
ModificadaAlta (7.8)4.8%💥 ExploitApache Http ServerOpenpkgHp-uxSlackware Linux+29/2/200516/6/2026
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
ModificadaBaja (1.2)0.31%—GetmailGentoo LinuxSlackware Linux27/1/200516/6/2026
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.
ModificadaBaja (2.1)0.39%—GetmailGentoo LinuxSlackware Linux27/1/200516/6/2026
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.
ModificadaAlta (10)6.9%—ROB Flynn GaimGentoo LinuxSlackware LinuxUbuntu Linux27/1/200516/6/2026
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
ModificadaBaja (2.1)1.1%💥 ExploitSGI PropackUtempterSlackware Linux18/8/200416/6/2026
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.
ModificadaMedia (5)2.9%—Midnight CommanderSGI PropackGentoo LinuxSlackware Linux18/8/200416/6/2026
Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
ModificadaBaja (2.1)0.38%—Midnight CommanderSGI PropackGentoo LinuxSlackware Linux18/8/200416/6/2026
Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."
ModificadaAlta (10)3.9%—Midnight CommanderSGI PropackGentoo LinuxSlackware Linux18/8/200416/6/2026
Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
ModificadaAlta (7.2)0.41%—PHPAISlackwareAI6/8/200416/6/2026
The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.
Orbitaley — Vulnerabilidades