Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.9% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+12 | 5/8/2021 | 17/6/2026 | When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's… | |
| Modificada | Media (6.5) | 4.3% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+12 | 5/8/2021 | 17/6/2026 | When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then… | |
| Modificada | Alta (8.8) | 18% | — | Google ChromeXmlsoft LibxsltDebian LinuxSplunk Universal Forwarder | 3/8/2021 | 17/6/2026 | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.8% | — | LibarchiveFedoraproject FedoraApple IpadosApple Iphone OS+3 | 20/7/2021 | 17/6/2026 | libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). | |
| Modificada | Alta (8.1) | 60% | — | Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+22 | 11/6/2021 | 17/6/2026 | curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at… | |
| Modificada | Baja (3.1) | 4.5% | — | Haxx CurlDebian LinuxFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+8 | 11/6/2021 | 17/6/2026 | curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data… | |
| Modificada | Media (5.3) | 3.0% | — | Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+18 | 11/6/2021 | 17/6/2026 | curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if… | |
| Modificada | Crítica (9.8) | 3.2% | — | LZ4 Project LZ4Netapp Active IQ Unified ManagerNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+3 | 2/6/2021 | 17/6/2026 | There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some… | |
| Modificada | Baja (3.7) | 3.1% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+7 | 1/4/2021 | 17/6/2026 | curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server… | |
| Modificada | Media (5.3) | 5.3% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+8 | 1/4/2021 | 17/6/2026 | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP… | |
| Modificada | Alta (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 14/12/2020 | 17/6/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modificada | Baja (3.7) | 3.9% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. | |
| Modificada | Alta (7.5) | 3.8% | — | Haxx LibcurlSiemens Sinec Infrastructure Network ServicesDebian LinuxOracle Communications Cloud Native Core Policy+1 | 14/12/2020 | 17/6/2026 | Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. | |
| Modificada | Alta (7.8) | 1.3% | — | Haxx CurlDebian LinuxFujitsu M10-1 FirmwareFujitsu M10-4 Firmware+6 | 14/12/2020 | 17/6/2026 | curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used. | |
| Modificada | Alta (7.5) | 3.5% | — | Haxx CurlSiemens Simatic TIM 1531 IRC FirmwareDebian LinuxSiemens Sinec Infrastructure Network Services+1 | 14/12/2020 | 17/6/2026 | curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). | |
| Modificada | Media (5.3) | 4.2% | — | PcreApple MacosGitlabOracle Communications Cloud Native Core Policy+11 | 15/6/2020 | 17/6/2026 | libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | |
| Modificada | Alta (7.5) | 2.8% | — | PcreApple MacosSplunk Universal Forwarder | 15/6/2020 | 17/6/2026 | libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454. | |
| Modificada | Alta (7.5) | 1.6% | — | Pcre2Fedoraproject FedoraSplunk Universal Forwarder | 14/2/2020 | 17/6/2026 | An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in… | |
| Modificada | Alta (7.5) | 1.9% | — | Forwarded Project Forwarded | 7/6/2018 | 17/6/2026 | The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of service when it's passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition. | |
| Modificada | Media (6.1) | 0.76% | — | Pressforward | 18/8/2017 | 17/6/2026 | Core\Admin\PFTemplater.php in the PressForward plugin 4.3.0 and earlier for WordPress has XSS in the PATH_INFO to wp-admin/admin.php, related to PHP_SELF. | |
| Modificada | Media (5.5) | 1.7% | — | Moneyforward Money Forward FOR ApppassMoneyforward Money Forward FOR AU SmartpassMoneyforward Money Forward FOR Chou HoudaiMoneyforward Money Forward FOR SBI Sumishin NET Bank+6 | 12/5/2017 | 17/6/2026 | The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for SHIGA BANK (prior to v1.2.0), Money Forward for SHIZUOKA BANK (prior to v1.4.0), Money Forward for SBI Sumishin Net Bank (prior to v1.6.0), Money Forward for Tokai Tokyo Securities (prior to… | |
| Modificada | Alta (7.8) | 1.4% | — | Moneyforward Money Forward FOR ApppassMoneyforward Money Forward FOR AU SmartpassMoneyforward Money Forward FOR Chou HoudaiMoneyforward Money Forward FOR SBI Sumishin NET Bank+6 | 12/5/2017 | 17/6/2026 | The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for SHIGA BANK (prior to v1.2.0), Money Forward for SHIZUOKA BANK (prior to v1.4.0), Money Forward for SBI Sumishin Net Bank (prior to v1.6.0), Money Forward for Tokai Tokyo Securities (prior to… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Etoshop C2C Forward Auction Creator | 21/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp. | |
| Modificada | Alta (10) | 2.2% | — | Zhou BO Message Forwarder | 15/3/2012 | 16/6/2026 | Unspecified vulnerability in the Message Forwarder (com.gmail.zbnetium) application 1.12.20110409.1 for Android has unknown impact and attack vectors. |