Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

5544 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)12%—PHPFedoraproject Fedora9/6/202417/6/2026
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as…
AnalizadaAlta (8.8)0.97%—Google ChromeFedoraproject Fedora30/5/202417/6/2026
Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.73%—Google ChromeFedoraproject Fedora30/5/202417/6/2026
Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.84%—Google ChromeFedoraproject Fedora30/5/202417/6/2026
Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.90%—Google ChromeFedoraproject Fedora30/5/202417/6/2026
Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.78%—Google ChromeFedoraproject Fedora30/5/202417/6/2026
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.76%—Google ChromeFedoraproject Fedora30/5/202417/6/2026
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.85%—Google ChromeFedoraproject Fedora30/5/202417/6/2026
Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (5.3)0.93%—F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora29/5/202417/6/2026
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
AnalizadaMedia (5.3)0.87%—F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora29/5/202417/6/2026
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
AnalizadaMedia (6.5)0.86%—F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora29/5/202417/6/2026
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
AnalizadaMedia (4.8)0.89%—F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora29/5/202417/6/2026
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility…
AnalizadaCrítica (9.6)7.5%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject Fedora28/5/202417/6/2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.61%—Google ChromeFedoraproject Fedora22/5/202417/6/2026
Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)0.64%—Google ChromeFedoraproject Fedora22/5/202417/6/2026
Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.1)0.61%—Google ChromeFedoraproject Fedora22/5/202417/6/2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.78%—Google ChromeFedoraproject Fedora22/5/202417/6/2026
Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.8)0.24%—Linux KernelFedoraproject Fedora20/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: btrfs: make sure that WRITTEN is set on all metadata blocks We previously would call btrfs_check_leaf() if we had the check integrity code enabled, which meant that we could only run the extended leaf checks if we had WRITTEN set on the header flags.…
AnalizadaMedia (5.5)0.27%—Linux KernelDebian LinuxFedoraproject Fedora19/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: dyndbg: fix old BUG_ON in >control parser Fix a BUG_ON from 2009. Even if it looks "unreachable" (I didn't really look), lets make sure by removing it, doing pr_err and return -EINVAL instead.
ModificadaCrítica (9.8)0.97%—QTFedoraproject Fedora18/5/202417/6/2026
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
AnalizadaAlta (7.5)17%—XENFedoraproject Fedora16/5/202417/6/2026
Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted.
AnalizadaMedia (6.5)8.5%—XENFedoraproject Fedora16/5/202417/6/2026
Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be able to set them to. When processing of hypercalls takes a considerable amount of…
ModificadaMedia (6.5)0.92%—Google ChromeFedoraproject Fedora15/5/202417/6/2026
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
AnalizadaMedia (6.5)0.95%—Google ChromeFedoraproject Fedora15/5/202417/6/2026
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaMedia (6.5)0.95%—Google ChromeFedoraproject Fedora15/5/202417/6/2026
Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)