Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Golang GOFedoraproject Fedora8/6/202317/6/2026
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. Flags containing embedded spaces are…
ModificadaCrítica (9.8)1.8%—Golang GOFedoraproject Fedora8/6/202317/6/2026
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. The arguments for a number of flags…
ModificadaAlta (7.8)0.43%—Golang GOFedoraproject Fedora8/6/202317/6/2026
En las plataformas Unix, el entorno de ejecución de Go no se comporta de forma diferente cuando se ejecuta un binario con los bits setuid/setgid. Esto puede ser peligroso en ciertos casos, como cuando se vuelca el estado de la memoria o se asume el estado de los descriptores de archivos de E/S estándar. Si se ejecuta…
ModificadaCrítica (9.8)1.7%—Golang GOFedoraproject Fedora8/6/202317/6/2026
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command,…
ModificadaMedia (6.5)1.4%—Freedesktop DbusFedoraproject FedoraDebian Linux8/6/202317/6/2026
D-Bus en versiones anteriores a v1.15.6 a veces permite a usuarios sin privilegios bloquear el "dbus-daemon". Si un usuario privilegiado con control sobre "dbus-daemon" está usando la interfaz "org.freedesktop.DBus.Monitoring" para monitorizar el tráfico del bus de mensajes, entonces un usuario sin privilegios con la…
ModificadaAlta (7.8)0.58%💥 PoCLibcap Project LibcapRedhat Enterprise LinuxFedoraproject FedoraDebian Linux6/6/202317/6/2026
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
ModificadaBaja (3.3)0.35%—Libcap Project LibcapRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora6/6/202317/6/2026
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
ModificadaMedia (6.5)1.1%—Yajl Project YajlFedoraproject FedoraDebian Linux6/6/202317/6/2026
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
AnalizadaAlta (8.8)32%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject FedoraDebian LinuxCouchbase Server5/6/20238/10/2026
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (5.3)0.74%—Debian LinuxFedoraproject FedoraQT5/6/202317/6/2026
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
AnalizadaAlta (7.8)3.1%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
ModificadaCrítica (9.8)8.0%💥 PoCImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
AnalizadaMedia (5.5)0.95%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+130/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
ModificadaBaja (3.7)2.2%—Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+526/5/202317/6/2026
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which…
ModificadaMedia (5.9)1.8%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+626/5/202317/6/2026
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private…
ModificadaMedia (6.1)3.0%💥 PoCPython RequestsFedoraproject Fedora26/5/202317/6/2026
Requests es una librería HTTP. Desde Requests 2.3.0, Requests ha estado filtrando cabeceras Proxy-Authorization a los servidores de destino cuando se redirige a un endpoint HTTPS. Esto es producto de cómo usamos `rebuild_proxies` para volver a adjuntar la cabecera `Proxy-Authorization` a las peticiones. Para…
ModificadaMedia (6.5)1.1%—LibsshFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,`…
ModificadaAlta (7.8)0.47%—Usebottles BottlesFedoraproject Fedora26/5/202317/6/2026
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
ModificadaMedia (5.5)0.39%—AvahiFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
ModificadaMedia (6.5)1.3%—LibsshFedoraproject FedoraDebian LinuxRedhat Enterprise Linux26/5/202317/6/2026
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
ModificadaAlta (7.5)1.6%—C-ares Project C-aresFedoraproject FedoraDebian Linux25/5/202317/6/2026
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the…
ModificadaMedia (6.5)0.90%—C-ares Project C-aresFedoraproject Fedora25/5/202317/6/2026
c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the random number generator is fed into a…
ModificadaMedia (6.4)0.38%—C-ares Project C-aresFedoraproject FedoraDebian Linux25/5/202317/6/2026
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an…
ModificadaBaja (3.7)0.93%—C-ares Project C-aresFedoraproject Fedora25/5/202317/6/2026
c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not…
ModificadaAlta (7.8)0.33%—Sysstat Project SysstatFedoraproject FedoraDebian Linux18/5/202317/6/2026
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.