Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.44% | — | Pbootcms | 30/11/2020 | 17/6/2026 | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. | |
| Modificada | Alta (7) | 0.36% | — | Linux KernelNetapp Cloud BackupNetapp Element SoftwareNetapp HCI Management Node+3 | 28/11/2020 | 17/6/2026 | An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1. | |
| Modificada | Media (6.1) | 1.7% | — | Snapappointments Bootstrap-select | 30/9/2020 | 17/6/2026 | bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser. | |
| Modificada | Crítica (9.1) | 1.1% | — | Linux4sam At91bootstrap | 14/9/2020 | 17/6/2026 | AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader). | |
| Modificada | Media (6.8) | 0.51% | — | Linux4sam At91bootstrap | 14/9/2020 | 17/6/2026 | A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected system. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php. | |
| Modificada | Baja (3.7) | 5.3% | — | Linux KernelOpensuse LeapFedoraproject FedoraDebian Linux+11 | 30/7/2020 | 17/6/2026 | The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c. | |
| Modificada | Media (6.5) | 5.2% | — | Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+20 | 18/5/2020 | 17/6/2026 | gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4. | |
| Modificada | Media (5.3) | 0.40% | — | Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+21 | 15/5/2020 | 17/6/2026 | The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+20 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails. | |
| Modificada | Media (6.7) | 0.59% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040. | |
| Modificada | Alta (7) | 0.40% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+19 | 29/4/2020 | 17/6/2026 | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur. | |
| Modificada | Alta (7.8) | 1.4% | — | Denx U-bootOpensuse Leap | 19/3/2020 | 17/6/2026 | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pbootcms | 2/3/2020 | 17/6/2026 | An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pbootcms | 2/3/2020 | 17/6/2026 | An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter. | |
| Modificada | Crítica (9.8) | 3.1% | — | Denx U-bootOpensuse Leap | 29/1/2020 | 17/6/2026 | In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static… | |
| Modificada | Media (5.5) | 0.39% | — | Trusted Boot Project Trusted BootRedhat Enterprise LinuxFedoraproject Fedora | 18/11/2019 | 17/6/2026 | Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability | |
| Modificada | Alta (8.1) | 3.8% | 💥 PoC | Libssh2Fedoraproject FedoraOpensuse LeapDebian Linux+6 | 21/10/2019 | 17/6/2026 | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service… |