Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 0.87% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.1) | 0.90% | — | Gnu-mailman Integration Project Gnu-mailman Integration | 10/9/2021 | 17/6/2026 | The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6. | |
| Modificada | Media (5.9) | 1.4% | — | Gnupg Libgcrypt | 6/9/2021 | 17/6/2026 | The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can… | |
| Modificada | Media (6.5) | 1.0% | — | GNU InetutilsDebian Linux | 3/9/2021 | 17/6/2026 | The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl. | |
| Modificada | Alta (7.5) | 3.0% | — | GNU GlibcFedoraproject FedoraOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native Environment+4 | 12/8/2021 | 17/6/2026 | In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix. | |
| Modificada | Alta (7.8) | 4.2% | 💥 PoC | GNU Cpio | 8/8/2021 | 17/6/2026 | GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data. | |
| Modificada | Crítica (9.1) | 2.6% | — | GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+3 | 22/7/2021 | 17/6/2026 | The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have… | |
| Modificada | Alta (7.8) | 0.55% | — | GNU AspellDebian LinuxFedoraproject Fedora | 20/7/2021 | 17/6/2026 | objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list). | |
| Modificada | Alta (8.8) | 1.3% | — | GNU Libredwg | 1/7/2021 | 17/6/2026 | GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object). | |
| Modificada | Media (6.1) | 1.1% | — | SIR Gnuboard | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php. | |
| Modificada | Crítica (9.8) | 5.4% | 💥 Exploit | SIR Gnuboard | 24/6/2021 | 17/6/2026 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | |
| Modificada | Media (6.1) | 1.1% | — | SIR Gnuboard | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Gnupg LibgcryptDebian LinuxFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+4 | 8/6/2021 | 17/6/2026 | Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP. | |
| Modificada | Alta (7.5) | 2.4% | — | GNU BinutilsNetapp Ontap Select Deploy Administration Utility | 2/6/2021 | 17/6/2026 | A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash. | |
| Modificada | Alta (7.5) | 1.3% | — | GNU Gama | 28/5/2021 | 17/6/2026 | A NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS) via segment faults caused by crafted inputs. | |
| Modificada | Alta (7.1) | 0.97% | — | GNU Binutils | 26/5/2021 | 17/6/2026 | An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system… | |
| Modificada | Crítica (9.8) | 2.9% | — | GNU GlibcFedoraproject FedoraNetapp Cloud BackupNetapp E-series Santricity OS Controller+9 | 25/5/2021 | 17/6/2026 | The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified… | |
| Modificada | Media (5.5) | 0.63% | — | GNU Libredwg | 18/5/2021 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file. | |
| Modificada | Media (5.5) | 0.42% | — | GNU CflowFedoraproject Fedora | 18/5/2021 | 17/6/2026 | Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135. |