Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.76% | — | Google ChromeDebian LinuxFedoraproject Fedora | 3/5/2023 | 17/6/2026 | Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium) | |
| Modificada | Alta (7.1) | 0.69% | — | Google ChromeDebian LinuxFedoraproject Fedora | 3/5/2023 | 17/6/2026 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.97% | — | Google ChromeDebian LinuxFedoraproject Fedora | 3/5/2023 | 17/6/2026 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (7.3) | 1.1% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 2/5/2023 | 17/6/2026 | The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database. | |
| Modificada | Media (5.3) | 6.6% | 💥 Exploit | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 2/5/2023 | 17/6/2026 | The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system. | |
| Analizada | Media (5.3) | 0.41% | — | Fedoraproject FedoraApple MacosNeovimVIM | 29/4/2023 | 24/9/2026 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499. | |
| Modificada | Media (5.5) | 0.26% | — | Canonical Cloud-initCanonical Ubuntu LinuxFedoraproject Fedora | 26/4/2023 | 17/6/2026 | Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege. | |
| Modificada | Alta (7.8) | 6.1% | 💥 PoC | Git-scm GITFedoraproject Fedora | 25/4/2023 | 17/6/2026 | Git es un sistema de control de revisiones. Antes de las versiones 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3 y 2.40.1, una versión especialmente El archivo `.gitmodules` elaborado con URL de submódulo que tienen más de 1024 caracteres se puede usar para explotar un error en… | |
| Modificada | Baja (2.2) | 0.96% | — | GIT FOR Windows Project GIT FOR WindowsFedoraproject Fedora | 25/4/2023 | 17/6/2026 | En Git para Windows, la versión de Git para Windows, no se envían mensajes localizados con el instalador. Como consecuencia, se espera que Git no localice ningún mensaje y omita la inicialización de gettext. Sin embargo, debido a un cambio en los paquetes MINGW, la inicialización implícita de la función `gettext()` ya… | |
| Modificada | Alta (7.5) | 52% | — | Git-scm GITFedoraproject Fedora | 25/4/2023 | 17/6/2026 | Git es un sistema de control de revisiones. Antes de las versiones 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3 y 2.40.1, mediante alimentación entrada especialmente manipulada para `git apply --reject`, una ruta fuera del árbol de trabajo se puede sobrescribir con contenidos… | |
| Modificada | Media (4.4) | 0.22% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+4 | 25/4/2023 | 8/10/2026 | A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. | |
| Modificada | Alta (7.8) | 0.26% | — | XENFedoraproject Fedora | 25/4/2023 | 17/6/2026 | x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for… | |
| Modificada | Media (6.5) | 0.97% | — | Getlaminas Laminas-diactorosGuzzlephp Psr-7Fedoraproject Fedora | 24/4/2023 | 17/6/2026 | Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a header key or value, can cause an invalid… | |
| Modificada | Media (5.5) | 0.41% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware | 24/4/2023 | 17/6/2026 | An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem)… | |
| Modificada | Media (6.7) | 0.24% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 20/4/2023 | 17/6/2026 | An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash… | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 5.7% | ⚠ Explotación activa | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.0% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (5.3) | 2.5% | — | Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython | 19/4/2023 | 17/6/2026 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after… | |
| Modificada | Media (6.5) | 1.3% | — | RedisDebian LinuxFedoraproject Fedora | 18/4/2023 | 17/6/2026 | Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Components Services). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Partition). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Media (4.9) | 1.5% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Partition). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… |