Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.3%—GNU GlibcOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+414/1/202217/6/2026
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a…
ModificadaCrítica (9.8)4.8%—GNU GlibcOracle Communications Cloud Native Core Unified Data RepositoryOracle Enterprise Operations MonitorDebian Linux14/1/202217/6/2026
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a…
ModificadaMedia (6.5)0.89%—GNU Libredwg1/1/202217/6/2026
LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).
ModificadaMedia (5.5)0.70%—GNU Patch22/12/202117/6/2026
An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.
ModificadaMedia (5.5)0.70%—Gnuplot21/12/202117/6/2026
A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.
ModificadaAlta (7.8)1.3%—GNU BinutilsFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+115/12/202117/6/2026
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
ModificadaMedia (6.1)1.8%💥 ExploitGnuboard514/12/202117/6/2026
gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaCrítica (9.8)1.4%—GNU Libredwg2/12/202117/6/2026
LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
ModificadaAlta (7.5)1.2%—GNU Libredwg2/12/202117/6/2026
LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
ModificadaAlta (8.8)0.76%—GNU MailmanDebian Linux2/12/202117/6/2026
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
ModificadaAlta (7.8)0.88%—GNU BinutilsGNU GCC18/11/202117/6/2026
GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.
ModificadaMedia (6.5)1.2%—GNU MailmanDebian Linux12/11/202117/6/2026
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.
ModificadaMedia (6.1)1.4%—GNU MailmanDebian Linux12/11/202117/6/2026
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.
ModificadaAlta (7)0.29%—GNU Hurd7/11/202117/6/2026
An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.
ModificadaAlta (8.8)2.0%—GNU Hurd7/11/202117/6/2026
An issue was discovered in GNU Hurd before 0.9 20210404-9. A single pager port is shared among everyone who mmaps a file, allowing anyone to modify any files that they can read. This can be trivially exploited to get full root access.
ModificadaAlta (7.8)0.36%—GNU Hurd7/11/202117/6/2026
An issue was discovered in GNU Hurd before 0.9 20210404-9. libports accepts fake notification messages from any client on any port, which can lead to port use-after-free. This can be exploited for local privilege escalation to get full root access.
ModificadaAlta (7.5)1.3%—GNU Hurd7/11/202117/6/2026
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to get full root access.
ModificadaAlta (7.5)3.3%—GNU GlibcOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+34/11/202117/6/2026
In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be…
ModificadaAlta (8)1.3%—GNU MailmanDebian Linux21/10/202117/6/2026
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
ModificadaMedia (4.3)1.3%—GNU MailmanDebian Linux21/10/202117/6/2026
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
ModificadaAlta (8.8)1.1%—GNU Libredwg20/9/202117/6/2026
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow.
ModificadaAlta (8.8)1.1%—GNU Libredwg20/9/202117/6/2026
An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.
ModificadaAlta (8.8)1.1%—GNU Libredwg20/9/202117/6/2026
An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.
ModificadaAlta (8.8)1.1%—GNU Libredwg20/9/202117/6/2026
An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow.
ModificadaMedia (6.5)0.86%—GNU Libredwg20/9/202117/6/2026
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.
Orbitaley — Vulnerabilidades