Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

699 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.44%—Pbootcms30/11/202017/6/2026
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
ModificadaAlta (7)0.36%—Linux KernelNetapp Cloud BackupNetapp Element SoftwareNetapp HCI Management Node+328/11/202017/6/2026
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
ModificadaMedia (6.1)1.7%—Snapappointments Bootstrap-select30/9/202017/6/2026
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
ModificadaCrítica (9.1)1.1%—Linux4sam At91bootstrap14/9/202017/6/2026
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).
ModificadaMedia (6.8)0.51%—Linux4sam At91bootstrap14/9/202017/6/2026
A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected system.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
ModificadaBaja (3.7)5.3%—Linux KernelOpensuse LeapFedoraproject FedoraDebian Linux+1130/7/202017/6/2026
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
ModificadaMedia (6.5)5.2%—Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2018/5/202017/6/2026
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
ModificadaMedia (5.3)0.40%—Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+2115/5/202017/6/2026
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
ModificadaMedia (5.5)0.52%—Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+209/5/202017/6/2026
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
ModificadaMedia (6.7)0.59%—Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+199/5/202017/6/2026
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.
ModificadaAlta (7)0.40%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1929/4/202017/6/2026
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur.
ModificadaAlta (7.8)1.4%—Denx U-bootOpensuse Leap19/3/202017/6/2026
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
ModificadaCrítica (9.8)1.8%—Pbootcms2/3/202017/6/2026
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
ModificadaCrítica (9.8)1.8%—Pbootcms2/3/202017/6/2026
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
ModificadaCrítica (9.8)3.1%—Denx U-bootOpensuse Leap29/1/202017/6/2026
In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static…
ModificadaMedia (5.5)0.39%—Trusted Boot Project Trusted BootRedhat Enterprise LinuxFedoraproject Fedora18/11/201917/6/2026
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
ModificadaAlta (8.1)3.8%💥 PoCLibssh2Fedoraproject FedoraOpensuse LeapDebian Linux+621/10/201917/6/2026
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service…
Orbitaley — Vulnerabilidades