Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

23.898 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.17%—Libexpat Project Libexpat21/6/202623/6/2026
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
AnalizadaMedia (6.9)0.17%—Libexpat Project Libexpat21/6/202623/6/2026
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
AnalizadaMedia (6.9)0.13%—Libexpat Project Libexpat21/6/202623/6/2026
libexpat before 2.8.2 has an integer overflow in getAttributeId.
AnalizadaMedia (6.9)0.13%—Libexpat Project Libexpat21/6/202623/6/2026
libexpat before 2.8.2 has an integer overflow in addBinding.
AnalizadaMedia (6.9)0.17%—Libexpat Project Libexpat21/6/202623/6/2026
libexpat before 2.8.2 has an integer overflow in storeAtts.
AnalizadaAlta (8.7)0.66%—Joomboost Joomproject19/6/202621/8/2026
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to…
AnalizadaAlta (8.8)0.49%—Gegabyte MY Projects19/6/202619/8/2026
Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract sensitive database…
AnalizadaMedia (6.9)0.10%—Libexpat Project Libexpat19/6/202623/6/2026
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
AnalizadaMedia (4.9)0.18%—Libexpat Project Libexpat19/6/202623/6/2026
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
AnalizadaCrítica (9.8)0.68%—Coturn Project Coturn18/6/202626/6/2026
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth access token (0-65535) is passed directly to memcpy() as the copy length into a 256-byte stack…
AnalizadaMedia (5.4)0.24%—Coturn Project Coturn18/6/202626/6/2026
Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/JavaScript that executes when an…
AplazadaMedia (5.3)0.42%—Mojolicious Sessions StorableAI18/6/202622/6/2026
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sources that are…
AnalizadaMedia (5.3)0.43%—Markdown-it Project Markdown-it17/6/202624/6/2026
markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per…
ModificadaAlta (7.1)0.28%—Zephyrproject Zephyr17/6/202614/7/2026
Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cind_handle(), which assigns a per-entry counter index and calls…
ModificadaAlta (7.5)0.93%—WS Project WS17/6/202611/9/2026
ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and…
AnalizadaMedia (6.1)0.34%—Carrierwave Project Carrierwave17/6/202618/6/2026
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in string entries, causing the denylist to silently not match the content types it is intended to block. In…
AnalizadaAlta (8.8)0.43%—Oracle Project Portfolio Analysis17/6/202618/6/2026
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio…
AnalizadaAlta (8.8)0.43%—Oracle Project Portfolio Analysis17/6/202618/6/2026
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio…
AnalizadaAlta (7.2)0.49%—Oracle Project Portfolio Analysis17/6/202618/6/2026
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Portfolio…
ModificadaAlta (7.1)0.37%—Zephyrproject Zephyr16/6/202614/7/2026
Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-interface ICMP-sent statistics by calling net_pkt_iface(pkt) after net_send_data(pkt) had already returned successfully. On the success path the network stack owns and releases…
ModificadaMedia (4.8)0.23%—Zephyrproject Zephyr16/6/20266/8/2026
In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_send_data(), and then, on success, calls net_stats_update_icmp_sent(net_pkt_iface(reply)). net_try_send_data() transfers ownership of reply to the TX path (net_if_try_queue_tx…
ModificadaAlta (7.5)0.35%—Zephyrproject Zephyr16/6/202617/7/2026
subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_request() and net_icmpv6_send_error(), the post-send statistics update calls net_pkt_iface(reply)/net_pkt_iface(pkt) on the just-sent packet. The send path…
ModificadaAlta (7.1)0.30%—Zephyrproject Zephyr16/6/202614/7/2026
subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network stack's ownership contract (include/zephyr/net/net_core.h, and the explicit warning in subsys/net/ip/net_core.c:453-460 'do not use pkt after that call'), a successful…
ModificadaBaja (3.7)0.31%—Zephyrproject Zephyr16/6/202614/7/2026
In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet had been handed to net_send_data(). On the successful-send path the packet's last reference may already have been released by the L2 driver or by the…
ModificadaMedia (6.3)0.16%—Zephyrproject Zephyr16/6/202614/7/2026
On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded inside the caller-owned struct k_mem_domain. When a domain is destroyed via k_mem_domain_deinit() ->…