Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Perl ImagerAI | 6/7/2026 | 6/7/2026 | Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads… | |
| Aplazada | Alta (7.5) | 0.51% | — | Perl Crypt DSAAI | 5/7/2026 | 6/7/2026 | Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. "Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. The signing nonce and the private key are… | |
| Aplazada | Media (5.9) | 0.51% | — | Perl CGI Session ID MD5AI | 1/7/2026 | 2/7/2026 | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All three are predictable, low-entropy sources: the PID is drawn from a… | |
| Aplazada | Alta (7.5) | 0.66% | — | Perl List Someutils XSAI | 25/6/2026 | 25/6/2026 | List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() collects the values returned by the block into a heap buffer sized to the longer input array, then grows the buffer before each copy with a single quadrupling (alloc <<= 2) instead of a loop. A block call… | |
| Aplazada | Crítica (9.1) | 0.37% | 💥 PoC | Perl SocketAI | 15/6/2026 | 17/6/2026 | Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a… | |
| Aplazada | Media (5.9) | 0.32% | — | Perl Crypt Pbkdf2AI | 12/6/2026 | 17/6/2026 | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key. | |
| Modificada | Crítica (9.8) | 0.82% | — | Perl DBI | 9/6/2026 | 3/9/2026 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow. | |
| Aplazada | Media (5.5) | 0.15% | — | Hyperledger Fabric-chaincode-javaAI | 8/6/2026 | 23/7/2026 | fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An… | |
| Analizada | Crítica (9.8) | 0.48% | — | Perl DBI | 5/6/2026 | 17/6/2026 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999… | |
| Aplazada | Alta (8.1) | 0.48% | — | Perl Sereal DecoderAI | 31/5/2026 | 22/7/2026 | Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_BINARY pattern (an… | |
| Aplazada | Media (6.2) | 0.19% | — | Perl Text LinefoldAI | 30/5/2026 | 22/7/2026 | Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just the segment. A side… | |
| Aplazada | Crítica (9.1) | 2.6% | — | Perl Http DaemonAI | 27/5/2026 | 23/7/2026 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input… | |
| Aplazada | Alta (7.3) | 0.50% | 💥 PoC | Perl IO CompressAI | 27/5/2026 | 5/8/2026 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A… | |
| Aplazada | Alta (7.3) | 0.41% | — | Perl IO CompressAI | 27/5/2026 | 24/7/2026 | IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to… | |
| Aplazada | Alta (7.5) | 0.61% | — | Perl IO Uncompress UnzipAI | 27/5/2026 | 24/7/2026 | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named… | |
| Aplazada | Media (5.5) | 0.13% | — | Perl IO Uncompress UnzipAI | 27/5/2026 | 24/7/2026 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range… | |
| Aplazada | Media (5.3) | 0.40% | — | Mojolicious Plugin StatsdAIPerl NET Statsd TinyAI | 26/5/2026 | 24/7/2026 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd client to using a… | |
| Modificada | Crítica (9.8) | 0.48% | — | Perl | 26/5/2026 | 8/9/2026 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes.… | |
| Aplazada | Media (5.1) | 0.18% | — | Perl Catalyst Plugin AuthenticationAI | 21/5/2026 | 23/7/2026 | Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. | |
| Aplazada | Crítica (9.8) | 0.80% | — | Perl Crypt Openssl Pkcs12AI | 17/5/2026 | 17/6/2026 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a… | |
| Aplazada | Media (6.5) | 0.36% | — | Perl Crypt DSAAI | 15/5/2026 | 17/6/2026 | Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified. | |
| Aplazada | Media (6.5) | 0.36% | — | Perl ImagerAI | 15/5/2026 | 17/6/2026 | Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates… | |
| Aplazada | Media (6.5) | 0.41% | — | Libwww-perl LWP UseragentAI | 12/5/2026 | 17/6/2026 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the… | |
| Aplazada | Media (6.5) | 0.36% | — | Perl Http TinyAI | 11/5/2026 | 17/6/2026 | HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values. An attacker who controls one of these inputs, for… | |
| Analizada | Crítica (9.3) | 0.63% | — | Hyperledger Fabric | 7/5/2026 | 25/8/2026 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an… |