Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.43% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 17/5/2023 | 17/6/2026 | A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service. | |
| Modificada | Alta (8.8) | 3.7% | — | Linuxfoundation Cups-filtersFedoraproject FedoraDebian Linux | 17/5/2023 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line… | |
| Modificada | Alta (8.8) | 0.68% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 25% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 29% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 15% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.85% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.87% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Modificada | Media (5.5) | 0.25% | — | Redhat LibvirtFedoraproject FedoraRedhat Enterprise Linux | 15/5/2023 | 17/6/2026 | A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup. | |
| Analizada | Media (6.5) | 1.3% | — | LibrawFedoraproject FedoraRedhat Enterprise Linux | 15/5/2023 | 17/6/2026 | A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash. | |
| Modificada | Media (5.9) | 0.74% | — | Videolan Dav1dFedoraproject Fedora | 10/5/2023 | 17/6/2026 | VideoLAN dav1d anterior a 1.2.0 tiene una condición de ejecución thread_task.c que puede provocar un bloqueo de la aplicación, relacionado con dav1d_decode_frame_exit. | |
| Modificada | Alta (7.5) | 6.1% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 9/5/2023 | 17/6/2026 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the… | |
| Modificada | Media (5.5) | 0.47% | — | VIMFedoraproject Fedora | 9/5/2023 | 23/6/2026 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531. | |
| Modificada | Alta (7.5) | 2.2% | — | FrroutingDebian LinuxFedoraproject Fedora | 9/5/2023 | 17/6/2026 | Un problema encontrado en Frrouting bgpd v.8.4.2 permite a un atacante remoto causar una denegación de servicio a través de la función bgp_attr_psid_sub(). | |
| Modificada | Media (5.5) | 1.0% | — | FrroutingFedoraproject Fedora | 9/5/2023 | 17/6/2026 | An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function. | |
| Modificada | Alta (7.5) | 1.1% | — | MaradnsFedoraproject FedoraDebian Linux | 9/5/2023 | 17/6/2026 | MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination. The vulnerability… | |
| Modificada | Crítica (9.8) | 1.4% | — | Djangoproject DjangoFedoraproject Fedora | 7/5/2023 | 17/6/2026 | In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading… | |
| Modificada | Media (6.5) | 0.93% | — | Struktur LibheifFedoraproject Fedora | 5/5/2023 | 17/6/2026 | A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service. | |
| Modificada | Media (4.3) | 0.80% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.82% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.80% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.65% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.86% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (4.3) | 0.80% | — | Google ChromeFedoraproject FedoraDebian Linux | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium) |