Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

23.898 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.30%—Zephyrproject Zephyr23/6/202617/7/2026
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descriptor (type), via net_buf_simple_pull_u8(). Because net_buf_simple_pull_u8()…
ModificadaMedia (5.5)0.16%—Zephyrproject Zephyr23/6/202614/7/2026
The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len when walking a directory block. ext2_fetch_direntry() guarded only with de_name_len > EXT2_MAX_FILE_NAME, but de_name_len is a uint8_t and EXT2_MAX_FILE_NAME is 255, so the check is always false;…
AnalizadaMedia (6.5)0.37%—Ultrajson Project Ultrajson22/6/202626/6/2026
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode…
AnalizadaMedia (6.1)0.27%—Pylonsproject Webob22/6/202626/6/2026
WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage…
AnalizadaMedia (6.9)0.16%—Pypdf Project Pypdf22/6/202624/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulnerability is fixed in 6.13.1.
AnalizadaMedia (6.9)0.17%—Pypdf Project Pypdf22/6/202625/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0.
AnalizadaMedia (6.9)0.17%—Pypdf Project Pypdf22/6/202625/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode. This vulnerability is fixed in 6.13.0.
AnalizadaMedia (6.9)0.17%—Pypdf Project Pypdf22/6/202625/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting the text of a page which contains a form XObject with self-references. This vulnerability is fixed in 6.12.2.
AnalizadaMedia (5.1)0.17%—Pypdf Project Pypdf22/6/202625/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2.
AplazadaMedia (5.3)0.31%—Astrojs NetlifyAI22/6/202623/6/2026
@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.13, @astrojs/netlify converts Astro image.remotePatterns into Netlify Image CDN images.remote_images regular expressions with broader semantics than Astro's canonical matcher. A single wildcard…
Pendiente de análisisAlta (7)0.19%—Alsa-project Alsa-libAI22/6/202614/7/2026
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check…
AnalizadaAlta (8.2)0.30%—Protobufjs Project Protobufjs-cli22/6/202624/6/2026
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected versions of protobufjs-cli could still emit unsafe JavaScript references when generating static output from crafted JSON…
AnalizadaMedia (5.3)0.40%—Protobufjs Project Protobufjs22/6/202624/6/2026
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$unknowns and did not provide a decode-time option to discard unknown fields before retaining them. A crafted protobuf payload containing many unknown fields could…
AnalizadaMedia (5.3)0.40%—Protobufjs Project ProtobufjsProtobufjs Project Protobufjs-cli22/6/202624/6/2026
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when…
AnalizadaAlta (7.5)0.46%—Protobufjs Project Protobufjs22/6/202626/6/2026
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted…
AnalizadaCrítica (9.3)0.61%—Misp-project Misp22/6/202623/6/2026
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka options such as plugin.library.paths to load…
AnalizadaAlta (8.7)0.69%—Misp-project Misp22/6/202623/6/2026
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could direct log output to a PHP file in a web-accessible directory and…
AnalizadaCrítica (9.3)0.46%—Misp-project Misp22/6/202626/6/2026
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the PHP session identifier (session_id()) as the OAuth state parameter.…
AnalizadaAlta (7.1)0.52%—Misp-project Misp22/6/202623/6/2026
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature permission could cause the application…
AnalizadaCrítica (9.4)0.47%💥 PoCMisp-project Misp22/6/202623/6/2026
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for each selected object. For Event Reports,…
AnalizadaMedia (5.9)0.18%—Libexpat Project Libexpat21/6/202623/6/2026
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
AnalizadaMedia (6.9)0.13%—Libexpat Project Libexpat21/6/202623/6/2026
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
AnalizadaMedia (6.9)0.13%—Libexpat Project Libexpat21/6/202623/6/2026
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
AnalizadaMedia (6.5)0.12%—Libexpat Project Libexpat21/6/202623/6/2026
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
AnalizadaMedia (6.9)0.13%—Libexpat Project Libexpat21/6/202623/6/2026
libexpat before 2.8.2 has an integer overflow in copyString.