Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2523▼ 417 respecto a la semana anterior
Críticas / altas1297▲ 13 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.98%—Apple Xcode18/12/201917/6/2026
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.
ModificadaAlta (7.8)0.98%—Apple Xcode18/12/201917/6/2026
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.
ModificadaAlta (7.8)0.98%—Apple Xcode18/12/201917/6/2026
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.
ModificadaAlta (8.8)1.9%—Apple Xcode18/12/201917/6/2026
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
ModificadaAlta (8.8)1.9%—Apple Xcode18/12/201917/6/2026
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
ModificadaAlta (8.8)1.8%—Apple Xcode18/12/201917/6/2026
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
ModificadaAlta (8.8)1.8%—Apple Xcode18/12/201917/6/2026
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
ModificadaCrítica (9.8)8.1%—Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+2029/7/201917/6/2026
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
ModificadaAlta (7.8)0.93%—Apple Xcode3/4/201917/6/2026
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10.
ModificadaAlta (8.8)9.3%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+1021/3/201917/6/2026
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
ModificadaMedia (6.1)9.8%—F5 NginxDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+17/11/201817/6/2026
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is…
ModificadaAlta (7.5)12%—F5 NginxDebian LinuxCanonical Ubuntu LinuxApple Xcode7/11/201817/6/2026
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
ModificadaAlta (7.5)47%—F5 NginxDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+17/11/201817/6/2026
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
ModificadaCrítica (9.8)2.4%—Apple Xcode3/4/201817/6/2026
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component.
ModificadaAlta (7.8)1.3%—Apple Xcode3/4/201817/6/2026
An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.
ModificadaAlta (7.8)1.6%—Apple Xcode23/10/201717/6/2026
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
ModificadaAlta (7.8)1.6%—Apple Xcode23/10/201717/6/2026
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
ModificadaAlta (7.8)1.6%—Apple Xcode23/10/201717/6/2026
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
ModificadaAlta (7.8)1.6%—Apple Xcode23/10/201717/6/2026
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.
ModificadaAlta (7.5)63%—F5 NginxPuppet EnterpriseApple Xcode13/7/201717/6/2026
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
ModificadaAlta (7.8)0.34%—Apple Xcode18/9/201617/6/2026
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4704.
ModificadaAlta (7.8)0.31%—Apple Xcode18/9/201617/6/2026
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4705.
ModificadaAlta (7.8)0.33%—Apple Xcode24/3/201617/6/2026
otool in Apple Xcode before 7.3 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors.
ModificadaMedia (5.3)8.7%—F5 NginxCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+115/2/201617/6/2026
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
ModificadaCrítica (9.8)8.9%—F5 NginxCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+115/2/201617/6/2026
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.