Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | Libjpeg-turbo | 25/5/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range, hence, an attacker could craft a 12-bit… | |
| Modificada | Media (6.5) | 0.57% | — | Jenkins Turboscript | 12/4/2023 | 17/6/2026 | A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository. | |
| Modificada | Crítica (9.8) | 0.86% | — | Turbogears Project Turbogears | 4/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in OnShift TurboGears 1.0.11.10. This affects an unknown part of the file turbogears/controllers.py of the component HTTP Header Handler. The manipulation leads to http response splitting. It is possible to initiate the attack remotely. Upgrading to version… | |
| Modificada | Media (5.5) | 0.28% | — | Libjpeg-turbo | 31/8/2022 | 17/6/2026 | A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo. | |
| Modificada | Media (5.5) | 1.1% | — | Libjpeg-turbo | 18/6/2022 | 17/6/2026 | The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c. | |
| Modificada | Alta (7.5) | 1.3% | — | Yonyou Turbocrm | 29/10/2021 | 17/6/2026 | SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information. | |
| Modificada | Media (4.8) | 0.55% | — | Yandex Turbo | 2/8/2021 | 17/6/2026 | The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 2.7% | — | Libjpeg-turbo | 1/6/2021 | 17/6/2026 | Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service. | |
| Modificada | Media (5.4) | 0.62% | — | Wpuslugi RSS FOR Yandex Turbo | 14/5/2021 | 17/6/2026 | The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issues | |
| Modificada | Media (6.5) | 1.2% | — | Libjpeg-turboFedoraproject Fedora | 10/3/2021 | 17/6/2026 | Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image. | |
| Modificada | Alta (8.1) | 3.2% | — | Libjpeg-turboMozilla Mozjpeg | 3/6/2020 | 17/6/2026 | libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Z61 Turbo Firmware | 14/11/2019 | 17/6/2026 | The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property… | |
| Modificada | Crítica (9.8) | 19% | — | Turbovnc | 29/10/2019 | 17/6/2026 | TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via network connectivity. To exploit this… | |
| Modificada | Media (5.5) | 0.95% | — | Libjpeg-turbo | 18/7/2019 | 17/6/2026 | In libjpeg-turbo 2.0.2, a large amount of memory can be used during processing of an invalid progressive JPEG image containing incorrect width and height values in the image header. NOTE: the vendor's expectation, for use cases in which this memory usage would be a denial of service, is that the application should… | |
| Modificada | Alta (7.3) | 0.35% | — | Intel Turbo Boost MAX Technology 3.0Lenovo Thinkstation P410 FirmwareLenovo Thinkstation P510 FirmwareLenovo Thinkstation P710 Firmware+1 | 13/6/2019 | 17/6/2026 | Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 3.1% | — | Libjpeg-turboMozilla MozjpegFedoraproject FedoraDebian Linux+1 | 7/3/2019 | 17/6/2026 | get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries. | |
| Modificada | Alta (8.8) | 2.0% | — | Libjpeg-turbo | 21/12/2018 | 17/6/2026 | The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench. | |
| Modificada | Media (6.5) | 1.7% | — | Libjpeg-turbo | 29/11/2018 | 17/6/2026 | libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg. | |
| Modificada | Media (6.5) | 3.4% | — | Libjpeg-turboCanonical Ubuntu LinuxDebian Linux | 18/6/2018 | 17/6/2026 | libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image. | |
| Modificada | Media (5.9) | 15% | — | Cavium Nitrox SSL SDKCavium Nitrox V SSL SDKCavium Octeon SDKCavium Octeon SSL SDK+10 | 5/3/2018 | 17/6/2026 | Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Media (6.5) | 2.4% | — | Libjpeg-turbo | 11/10/2017 | 17/6/2026 | libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file. | |
| Modificada | Media (6.5) | 3.2% | — | Libjpeg-turboFedoraproject FedoraCanonical Ubuntu Linux | 10/10/2017 | 17/6/2026 | libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker. | |
| Modificada | Alta (8.8) | 8.2% | 💥 Exploit | D.r.commander Libjpeg-turbo | 27/7/2017 | 17/6/2026 | The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse… | |
| Modificada | Alta (8.8) | 4.4% | — | Libjpeg-turboRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux | 13/2/2017 | 17/6/2026 | The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file. | |
| Modificada | Alta (7.8) | 1.8% | — | IIJ Seil Plus FirmwareIIJ Seil PlusIIJ Seil B1 FirmwareIIJ Seil X1 Firmware+4 | 5/12/2014 | 17/6/2026 | The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SEIL/x86 Fuji 1.00 through 3.22; SEIL/X1, SEIL/X2, and SEIL/B1 1.00 through 4.62; SEIL/Turbo 1.82 through 2.18; and SEIL/neu 2FE Plus 1.82 through 2.18 allow remote attackers to cause a denial of… |