Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.4%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux16/6/202217/6/2026
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
ModificadaAlta (7.8)1.4%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux16/6/202217/6/2026
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
ModificadaAlta (7.5)2.8%—FreerdpFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora26/4/202217/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is…
ModificadaAlta (7.5)4.2%—Golang GOFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora20/4/202217/6/2026
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
ModificadaCrítica (9.8)4.9%—GITFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux19/4/202217/6/2026
The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command…
ModificadaAlta (8.8)0.93%—MoodleFedoraproject FedoraFedoraproject Extra Packages FOR Enterprise Linux25/3/202217/6/2026
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
ModificadaAlta (7.5)3.9%—Golang SSHFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Advanced Cluster Management FOR Kubernetes18/3/202217/6/2026
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
ModificadaAlta (7.5)2.5%💥 PoCKeepassFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora10/3/202217/6/2026
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
ModificadaMedia (6.5)4.7%—PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+1610/3/202217/6/2026
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to…
ModificadaAlta (7.8)1.2%—BlenderFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux24/2/202217/6/2026
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
ModificadaAlta (7.5)6.0%—Prometheus Client GolangFedoraproject FedoraFedoraproject Extra Packages FOR Enterprise LinuxRDO Project RDO15/2/202217/6/2026
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory…
ModificadaMedia (6.1)1.3%—Phoronix-media Phoronix Test SuiteFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora14/2/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
ModificadaCrítica (9.1)2.8%—StrongswanDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+131/1/202217/6/2026
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
ModificadaMedia (5.5)1.1%—Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+36/1/202217/6/2026
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
ModificadaMedia (5.5)1.1%—Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+36/1/202217/6/2026
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
ModificadaAlta (7.5)3.9%—Celeryproject CeleryFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora29/12/202117/6/2026
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could…
ModificadaMedia (5.3)1.0%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora22/11/202117/6/2026
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
ModificadaAlta (8.8)0.63%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora22/11/202117/6/2026
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
ModificadaMedia (6.1)0.87%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora22/11/202117/6/2026
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
ModificadaAlta (8.8)2.9%—Ribbonsoft DxflibFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux8/9/202117/6/2026
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (8.8)2.8%—Plib Project PlibDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora24/8/202117/6/2026
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
ModificadaAlta (7.4)1.9%—Mbsync Project MbsyncFedoraproject Extra Packages FOR Enterprise LinuxDebian LinuxFedoraproject Fedora23/2/202117/6/2026
A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the…
ModificadaMedia (5.5)1.5%—Uclouvain OpenjpegFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+75/1/202117/6/2026
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
ModificadaBaja (3.3)1.2%💥 PoCLibpng PngcheckFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux8/12/202017/6/2026
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
ModificadaAlta (7.5)6.0%💥 ExploitPureftpd Pure-ftpdDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+126/2/202017/6/2026
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member.…
Orbitaley — Vulnerabilidades