Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.26% | — | Jasper Project Jasper | 16/1/2024 | 17/6/2026 | An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code. | |
| Modificada | Media (6.8) | 0.54% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 15/1/2024 | 17/6/2026 | An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a… | |
| Modificada | Alta (7.5) | 1.3% | — | Freefloat FTP Server Project Freefloat FTP Server | 15/1/2024 | 17/6/2026 | A vulnerability was found in FreeFloat FTP Server 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component SIZE Command Handler. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (5.5) | 0.29% | — | Relax-and-recoverSuse Linux EnterpriseRedhat Enterprise LinuxFedoraproject Fedora | 12/1/2024 | 17/6/2026 | Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root. | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 12/1/2024 | 21/7/2026 | A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency… | |
| Modificada | Media (5.3) | 0.44% | — | Google ChromeFedoraproject Fedora | 10/1/2024 | 17/6/2026 | Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.1) | 2.6% | — | RedisFedoraproject Fedora | 10/1/2024 | 17/6/2026 | Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4. | |
| Modificada | Media (6.5) | 0.57% | — | FreeipaFedoraproject FedoraRedhat Codeready Linux BuilderRedhat Enterprise Linux+17 | 10/1/2024 | 17/6/2026 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration… | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux | 8/1/2024 | 17/6/2026 | It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code. | |
| Analizada | Media (5.3) | 1.3% | — | Debian LinuxFedoraproject FedoraJnunemaker Httparty | 4/1/2024 | 14/7/2026 | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. | |
| Modificada | Alta (7) | 0.41% | — | Debian LinuxLinux KernelFedoraproject Fedora | 4/1/2024 | 17/6/2026 | A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial… | |
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.0% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 10% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject Fedora | 4/1/2024 | 17/6/2026 | Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Baja (3.3) | 0.23% | — | Packagekit Project PackagekitRedhat Enterprise LinuxFedoraproject Fedora | 3/1/2024 | 17/6/2026 | A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored… | |
| Modificada | Media (4.8) | 0.45% | — | LibsshFedoraproject FedoraRedhat Enterprise Linux | 3/1/2024 | 17/6/2026 | A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter. | |
| Modificada | Media (5.3) | 0.33% | — | QemuRedhat Enterprise LinuxFedoraproject Fedora | 2/1/2024 | 17/6/2026 | A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables… | |
| Modificada | Alta (7.3) | 1.2% | — | SqliteFedoraproject Fedora | 29/12/2023 | 17/6/2026 | A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this… | |
| Modificada | Media (6.1) | 0.36% | — | Zephyr Project Manager Project Zephyr Project Manager | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9. | |
| Modificada | Alta (8.8) | 0.48% | — | MF GIG Calendar Project MF GIG Calendar | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1. | |
| Modificada | Crítica (9.8) | 1.2% | — | AomediaFedoraproject Fedora | 27/12/2023 | 23/6/2026 | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). | |
| Analizada | Alta (7.8) | 19% | ⚠ Explotación activa💥 Exploit | Jmcnamara Spreadsheet\Debian LinuxFedoraproject Fedora | 24/12/2023 | 17/6/2026 | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings… | |
| Modificada | Alta (7) | 0.66% | — | Openbsd OpensshFedoraproject FedoraRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the… | |
| Modificada | Media (5.3) | 1.1% | — | EximFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 24/12/2023 | 17/6/2026 | Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other… |