Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 482 respecto a la semana anterior
Críticas / altas1306▼ 184 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.5)0.47%—GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+96/7/202217/6/2026
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman…
ModificadaMedia (4.5)0.46%—GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+106/7/202217/6/2026
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform…
ModificadaMedia (6.5)2.8%—GnupgFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+11/7/202217/6/2026
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.
ModificadaAlta (7.8)0.79%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.
ModificadaAlta (7.8)0.75%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
ModificadaAlta (7.8)0.79%—GNU Libredwg23/6/202217/6/2026
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.
ModificadaAlta (7.5)1.1%—GNU Libredwg23/6/202217/6/2026
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
ModificadaMedia (6.1)0.85%—Mailerlite Signup Forms13/6/202217/6/2026
The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)1.0%—GNU Libredwg23/5/202217/6/2026
A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
ModificadaAlta (8.8)1.0%—GNU Libredwg23/5/202217/6/2026
A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
ModificadaMedia (6.1)0.72%—SIR Gnuboard16/5/202217/6/2026
Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.
ModificadaAlta (7.5)1.5%—Bignum Project Bignum6/5/202217/6/2026
All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.
ModificadaCrítica (9.1)0.55%—SIR Gnuboard11/4/202217/6/2026
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the email address of any user, including when…
ModificadaMedia (5.5)0.91%—GNU GCCFedoraproject Fedora26/3/202217/6/2026
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
ModificadaMedia (4.4)0.24%—GNU Grub216/3/202217/6/2026
A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to…
ModificadaBaja (3.3)0.32%—GNU Grub2Fedoraproject Fedora10/3/202217/6/2026
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw…
ModificadaAlta (8.8)0.82%—Xootix Login/signup PopupXootix Side Cart WoocommerceXootix Waitlist Woocommerce18/1/202217/6/2026
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for…
ModificadaMedia (5.5)0.78%—GNU GCC14/1/202217/6/2026
GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.
ModificadaMedia (5.5)0.97%—GNU RecutilsFedoraproject Fedora14/1/202217/6/2026
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
ModificadaMedia (5.5)0.95%—GNU RecutilsFedoraproject Fedora14/1/202217/6/2026
An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
ModificadaMedia (5.5)1.0%—GNU RecutilsFedoraproject Fedora14/1/202217/6/2026
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
Orbitaley — Vulnerabilidades