Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.1%—GNU Libredwg20/9/202117/6/2026
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow.
ModificadaMedia (6.5)0.87%—GNU Libredwg20/9/202117/6/2026
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.
ModificadaMedia (6.1)0.90%—Gnu-mailman Integration Project Gnu-mailman Integration10/9/202117/6/2026
The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.
ModificadaMedia (5.9)1.4%—Gnupg Libgcrypt6/9/202117/6/2026
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can…
ModificadaMedia (6.5)1.0%—GNU InetutilsDebian Linux3/9/202117/6/2026
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
ModificadaAlta (7.5)3.0%—GNU GlibcFedoraproject FedoraOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native Environment+412/8/202117/6/2026
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
ModificadaAlta (7.8)4.2%💥 PoCGNU Cpio8/8/202117/6/2026
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
ModificadaCrítica (9.1)2.6%—GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+322/7/202117/6/2026
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have…
ModificadaAlta (7.8)0.55%—GNU AspellDebian LinuxFedoraproject Fedora20/7/202117/6/2026
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
ModificadaAlta (8.8)1.3%—GNU Libredwg1/7/202117/6/2026
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).
ModificadaMedia (6.1)1.1%—SIR Gnuboard24/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.
ModificadaCrítica (9.8)5.4%💥 ExploitSIR Gnuboard24/6/202117/6/2026
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
ModificadaMedia (6.1)1.1%—SIR Gnuboard24/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.
ModificadaAlta (7.5)2.3%💥 PoCGnupg LibgcryptDebian LinuxFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+48/6/202117/6/2026
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
ModificadaAlta (7.5)2.4%—GNU BinutilsNetapp Ontap Select Deploy Administration Utility2/6/202117/6/2026
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
ModificadaAlta (7.5)1.3%—GNU Gama28/5/202117/6/2026
A NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS) via segment faults caused by crafted inputs.
ModificadaAlta (7.1)0.97%—GNU Binutils26/5/202117/6/2026
An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system…
ModificadaCrítica (9.8)2.9%—GNU GlibcFedoraproject FedoraNetapp Cloud BackupNetapp E-series Santricity OS Controller+925/5/202117/6/2026
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified…
ModificadaMedia (5.5)0.63%—GNU Libredwg18/5/202117/6/2026
A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.
ModificadaMedia (5.5)0.42%—GNU CflowFedoraproject Fedora18/5/202117/6/2026
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
ModificadaAlta (8.8)1.5%—GNU Libredwg17/5/20219/7/2026
GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580.
ModificadaAlta (8.8)1.1%—GNU Libredwg17/5/20219/7/2026
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318.
ModificadaAlta (8.8)1.1%—GNU Libredwg17/5/20219/7/2026
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051.
ModificadaAlta (8.8)1.1%—GNU Libredwg17/5/20219/7/2026
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637.
ModificadaAlta (8.8)1.1%—GNU Libredwg17/5/20219/7/2026
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.
Orbitaley — Vulnerabilidades