Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Sparkdevnetwork Rock RMS | 7/1/2021 | 17/6/2026 | Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any user to change account details of any other user. This vulnerability could be used to change the email address of another… | |
| Modificada | Alta (7.8) | 0.43% | — | KDE Partition Manager | 26/10/2020 | 17/6/2026 | An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker on the local machine can replace /etc/fstab, and execute mount and other partitioning related commands, while KDE… | |
| Modificada | Media (5.5) | 0.55% | — | KdeconnectOpensuse Backports SLEOpensuse Leap | 7/10/2020 | 17/6/2026 | In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack. | |
| Modificada | Baja (3.3) | 1.5% | — | KDE ARKCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 2/9/2020 | 17/6/2026 | In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. | |
| Modificada | Baja (3.3) | 1.7% | — | KDE ARKDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 3/8/2020 | 17/6/2026 | In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal. | |
| Modificada | Media (6.5) | 0.65% | — | KDE KmailDebian Linux | 27/7/2020 | 17/6/2026 | KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use. | |
| Modificada | Media (5.5) | 3.4% | 💥 Exploit | KDE Amarok | 20/5/2020 | 17/6/2026 | A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Amarok 2.8.0 continue to waste resources over time, eventually allows attackers to cause a denial of service. | |
| Modificada | Baja (3.3) | 0.37% | — | KDE Kio-extras | 9/5/2020 | 17/6/2026 | fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password. | |
| Modificada | Media (6.5) | 0.85% | — | KDE Kmail | 17/4/2020 | 17/6/2026 | An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make KMail attach local files to a composed email message without showing a warning to the user, as demonstrated by an attach=.bash_history value. | |
| Modificada | Media (5.3) | 1.5% | — | KDE OkularDebian LinuxFedoraproject Fedora | 24/3/2020 | 17/6/2026 | KDE Okular before 1.10.0 allows code execution via an action link in a PDF document. | |
| Modificada | Crítica (9.8) | 3.4% | — | Sparkdevnetwork Rock RMS | 20/3/2020 | 17/6/2026 | Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller. | |
| Modificada | Media (5.3) | 1.1% | — | KDE Applications | 12/3/2020 | 17/6/2026 | messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value. | |
| Modificada | Media (5.5) | 0.31% | — | KDE Paste Applet | 11/2/2020 | 16/6/2026 | The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output. | |
| Modificada | Alta (8.4) | 0.56% | — | KDE Paste Applet | 11/2/2020 | 16/6/2026 | The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack. | |
| Modificada | Alta (8.8) | 12% | 💥 Exploit | KDERedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server EUS+1 | 8/2/2020 | 16/6/2026 | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion." | |
| Modificada | Media (6.1) | 0.86% | — | Clickdesk | 14/1/2020 | 17/6/2026 | ClickDesk version 4.3 and below has persistent cross site scripting | |
| Modificada | Alta (7.5) | 2.8% | — | Kde-workspaceDebian Linux | 10/12/2019 | 16/6/2026 | kde-workspace before 4.10.5 has a memory leak in plasma desktop | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Duckdev 404 TO 301 | 16/8/2019 | 17/6/2026 | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. | |
| Modificada | Alta (7.8) | 4.1% | — | KDE KconfigDebian LinuxFedoraproject FedoraOpensuse Backports SLE+4 | 7/8/2019 | 17/6/2026 | In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file. | |
| Modificada | Alta (8.1) | 2.4% | — | KDE KauthOpensuse LeapOpensuse BackportsFedoraproject Fedora | 7/5/2019 | 17/6/2026 | KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run… | |
| Modificada | Media (4.3) | 0.59% | — | KDE KmailDebian Linux | 7/4/2019 | 17/6/2026 | In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If… | |
| Modificada | Alta (7.5) | 1.5% | — | KDE Applications | 29/11/2018 | 17/6/2026 | The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address. | |
| Modificada | Media (5.5) | 1.8% | — | KDE OkularDebian Linux | 6/9/2018 | 17/6/2026 | okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue… | |
| Modificada | Media (5.9) | 4.1% | — | 9folders NineApple MailBloop AirmailEmclient+13 | 16/5/2018 | 17/6/2026 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | |
| Modificada | Alta (7.8) | 0.45% | — | KDE PlasmaDebian LinuxOpensuse Leap | 8/5/2018 | 17/6/2026 | kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack. |