Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.65% | — | Pbootcms | 10/10/2019 | 17/6/2026 | PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs. | |
| Modificada | Media (6.1) | 1.5% | — | Bootstrap-3-typeahead Project Bootstrap-3-typeahead | 8/10/2019 | 17/6/2026 | Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser. | |
| Modificada | Crítica (9.8) | 1.5% | — | Idcos Cloudboot | 30/9/2019 | 17/6/2026 | CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI. | |
| Modificada | Media (5.4) | 0.75% | — | Bootstrapped WP Ultimate Recipe | 30/8/2019 | 17/6/2026 | The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. | |
| Modificada | Alta (7.8) | 1.8% | — | Denx U-bootOpensuse Leap | 6/8/2019 | 17/6/2026 | Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution. | |
| Modificada | Alta (7.8) | 1.3% | — | Denx U-boot | 6/8/2019 | 17/6/2026 | Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem. | |
| Modificada | Alta (7.8) | 1.1% | — | Denx U-bootOpensuse Leap | 6/8/2019 | 17/6/2026 | In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem. | |
| Modificada | Crítica (9.8) | 2.7% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply. | |
| Modificada | Crítica (9.8) | 2.6% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply. | |
| Modificada | Crítica (9.8) | 2.6% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply. | |
| Modificada | Crítica (9.8) | 2.6% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply. | |
| Modificada | Crítica (9.8) | 2.6% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply. | |
| Modificada | Crítica (9.8) | 2.4% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call. | |
| Modificada | Crítica (9.8) | 2.4% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case. | |
| Modificada | Crítica (9.1) | 2.5% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply. | |
| Modificada | Crítica (9.8) | 2.1% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply. | |
| Modificada | Crítica (9.8) | 2.5% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length. | |
| Modificada | Crítica (9.8) | 2.4% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case. | |
| Modificada | Crítica (9.8) | 2.6% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length. | |
| Modificada | Crítica (9.8) | 2.8% | — | Denx U-boot | 31/7/2019 | 17/6/2026 | An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call. | |
| Modificada | Alta (7.1) | 0.43% | — | Denx U-boot | 29/7/2019 | 17/6/2026 | A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data. | |
| Modificada | Alta (7.8) | 0.57% | — | Redhat Virt-bootstrap | 5/7/2019 | 17/6/2026 | virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py. | |
| Modificada | Media (5.9) | 9.7% | — | Apache ActivemqApache DrillApache ZookeeperDebian Linux+6 | 23/5/2019 | 17/6/2026 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id… | |
| Modificada | Crítica (9.8) | 1.9% | — | Denx U-boot | 10/5/2019 | 17/6/2026 | Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow. | |
| Modificada | Media (5.9) | 1.2% | — | Denx U-boot | 3/5/2019 | 17/6/2026 | gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device. |