Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
6915 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.33% | — | Google ChromeFedoraproject Fedora | 29/7/2023 | 17/6/2026 | Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject FedoraDebian Linux | 29/7/2023 | 17/6/2026 | Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (5.4) | 0.37% | — | MF GIG Calendar Project MF GIG Calendar | 27/7/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Matthew Fries MF Gig Calendar plugin <= 1.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Custom Field FOR WP JOB Manager Project Custom Field FOR WP JOB Manager | 27/7/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Custom Field For WP Job Manager plugin <= 1.1 versions. | |
| Analizada | Crítica (9.8) | 0.57% | — | CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+4 | 25/7/2023 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of… | |
| Modificada | Media (4.4) | 0.25% | — | Redhat Enterprise LinuxFedoraproject FedoraLinux KernelDebian Linux | 25/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to… | |
| Modificada | Media (4.4) | 0.45% | — | Redhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFVFedoraproject Fedora+2 | 25/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service. | |
| Modificada | Media (4.8) | 0.37% | — | Login Configurator Project Login Configurator | 25/7/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Recent Posts Slider Project Recent Posts Slider | 25/7/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions. | |
| Modificada | Alta (7.5) | 1.4% | — | KeylimeRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+5 | 24/7/2023 | 17/6/2026 | Se encontró una falla en Keylime. Debido a su naturaleza de bloqueo, el registrador de Keylime está sujeto a una denegación de servicio remota contra sus conexiones SSL. Esta falla permite a un atacante agotar todas las conexiones disponibles. | |
| Modificada | Alta (7.8) | 0.24% | — | QemuFedoraproject Fedora | 24/7/2023 | 17/6/2026 | A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their… | |
| Modificada | Media (5.5) | 2.3% | — | Gnome LibrsvgFedoraproject FedoraDebian Linux | 22/7/2023 | 17/6/2026 | A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element. | |
| Modificada | Media (5.4) | 0.62% | — | Tiva Events Calendar Project Tiva Events Calendar | 20/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the… | |
| Modificada | Media (5.9) | 0.44% | — | SambaRedhat StorageRedhat Enterprise LinuxFedoraproject Fedora | 20/7/2023 | 17/6/2026 | A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a… | |
| Modificada | Media (5.3) | 1.3% | — | SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+1 | 20/7/2023 | 17/6/2026 | A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part… | |
| Modificada | Media (5.3) | 61% | — | SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 20/7/2023 | 17/6/2026 | A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of… | |
| Modificada | Alta (7.5) | 62% | — | SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 20/7/2023 | 17/6/2026 | An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing… | |
| Modificada | Media (5.9) | 1.7% | — | SambaRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 20/7/2023 | 17/6/2026 | An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length.… | |
| Modificada | Media (5.4) | 0.57% | — | Wifi File Explorer Project Wifi File Explorer | 20/7/2023 | 17/6/2026 | A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Media (5.4) | 0.60% | — | Webile Wifi PC File Transfer Project Webile Wifi PC File Transfer | 20/7/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en Webile v1.0.1. Se ha clasificado como problemática. Una función desconocida del componente "HTTP POST Request Handler" es la afectada. La manipulación del argumento "new_file_name/c" conduce a Cross-Site Scripting (XSS). Es posible lanzar el ataque de forma remota. El exploit ha… | |
| Modificada | Crítica (9.8) | 80% | 💥 PoC | Openbsd OpensshFedoraproject Fedora | 20/7/2023 | 17/6/2026 | La característica PKCS#11 en ssh-agent en OpenSSH anterior a 9.3p2 tiene una ruta de búsqueda insuficientemente confiable, lo que lleva a la ejecución remota de código si un agente se reenvía a un sistema controlado por un atacante. (El código en /usr/lib no es necesariamente seguro para cargar en ssh-agent). NOTA:… | |
| Modificada | Baja (2.8) | 0.21% | — | KeylimeFedoraproject Fedora | 19/7/2023 | 17/6/2026 | A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted. | |
| Modificada | Media (4.4) | 1.7% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: DDL). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques exitosos de… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Replication). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Media (4.9) | 1.8% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Optimizer). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… |