Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.5%—GNU Chess29/8/201917/6/2026
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
ModificadaMedia (6.1)1.4%—SIR Gnuboard26/8/201917/6/2026
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter.
ModificadaMedia (6.5)1.7%—GNU LibextractorDebian LinuxFedoraproject Fedora23/8/201917/6/2026
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
ModificadaMedia (6.1)0.92%—SIR Gnucommerce22/8/201917/6/2026
The gnucommerce plugin before 1.4.2 for WordPress has XSS.
ModificadaMedia (6.1)0.92%—SIR Gnucommerce22/8/201917/6/2026
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
ModificadaAlta (7.8)2.7%—GNU Patch16/8/201917/6/2026
do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.
ModificadaCrítica (9.8)4.1%—Windriver VxworksBelden Hirschmann HiosBelden Garrettcom Magnum Dx940e FirmwareSiemens Ruggedcom Win7000 Firmware+314/8/201917/6/2026
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
ModificadaAlta (7.5)1.2%—GNU Exosip14/8/201917/6/2026
handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
ModificadaCrítica (9.8)9.0%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+99/8/201917/6/2026
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
ModificadaCrítica (9.8)23%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+99/8/201917/6/2026
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
ModificadaAlta (7.5)23%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+89/8/201917/6/2026
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
ModificadaCrítica (9.8)75%💥 ExploitWindriver VxworksNetapp E-series Santricity OS ControllerSonicwall SonicosSiemens Siprotec 5 Firmware+89/8/201917/6/2026
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
ModificadaMedia (5.3)60%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+89/8/201917/6/2026
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
ModificadaAlta (8.1)3.2%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+89/8/201917/6/2026
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
ModificadaAlta (7.5)16%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareSiemens Ruggedcom Win7000 Firmware+79/8/201917/6/2026
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.
ModificadaAlta (8.8)84%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+69/8/201917/6/2026
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.
ModificadaCrítica (9.8)27%—Windriver VxworksNetapp E-series Santricity OS ControllerSonicwall SonicosSiemens Siprotec 5 Firmware+89/8/201917/6/2026
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
ModificadaAlta (7.1)8.3%—Windriver VxworksBelden Hirschmann HiosBelden Garrettcom Magnum Dx940e FirmwareSiemens Ruggedcom Win7000 Firmware+35/8/201917/6/2026
Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.
ModificadaAlta (7.8)1.1%—Gnucobol Project Gnucobol2/8/201917/6/2026
GnuCOBOL 2.2 has a stack-based buffer overflow in cb_encode_program_id in cobc/typeck.c via crafted COBOL source code.
ModificadaAlta (7.8)0.97%—Gnucobol Project Gnucobol2/8/201917/6/2026
GnuCOBOL 2.2 has a heap-based buffer overflow in read_literal in cobc/scanner.l via crafted COBOL source code.
ModificadaAlta (7.8)0.97%—Gnucobol Project Gnucobol1/8/201917/6/2026
GnuCOBOL 2.2 has a buffer overflow in cb_evaluate_expr in cobc/field.c via crafted COBOL source code.
ModificadaAlta (7.8)1.0%—Gnucobol Project Gnucobol1/8/201917/6/2026
GnuCOBOL 2.2 has a buffer overflow in cb_push_op in cobc/field.c via crafted COBOL source code.
ModificadaMedia (5.5)1.5%—GNU BinutilsOpensuse LeapCanonical Ubuntu LinuxNetapp HCI Management Node+130/7/201917/6/2026
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
ModificadaAlta (7.8)4.5%—GNU PatchDebian Linux26/7/201917/6/2026
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.
ModificadaAlta (7.8)2.6%—GNU GDBOpensuse Leap24/7/201917/6/2026
GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet.
Orbitaley — Vulnerabilidades