Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
6915 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.39% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure. | |
| Modificada | Alta (7.8) | 0.27% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure. | |
| Modificada | Media (5.5) | 0.28% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. | |
| Modificada | Media (5.5) | 0.21% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. | |
| Modificada | Alta (8.8) | 0.33% | — | WP Dummy Content Generator Project WP Dummy Content Generator | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions. | |
| Modificada | Alta (8.8) | 0.33% | — | Webwinkelkeur Project Webwinkelkeur | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Albert Peschar WebwinkelKeur plugin <= 3.24 versions. | |
| Modificada | Media (4.8) | 0.54% | — | Image Protector Project Image Protector | 10/7/2023 | 17/6/2026 | The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.5) | 65% | — | LibreofficeFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. | |
| Modificada | Alta (8.2) | 1.0% | — | Youtube-dlc Project Youtube-dlcYt-dl Youtube-dlYt-dlp Project Yt-dlpFedoraproject Fedora | 6/7/2023 | 17/6/2026 | yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them when the host for download fragments differs from their parent manifest's host. This vulnerable… | |
| Modificada | Alta (7.8) | 1.5% | 💥 PoC | Linux KernelDebian LinuxFedoraproject FedoraNetapp H300s+4 | 5/7/2023 | 17/6/2026 | Vulnerabilidad de Lectura/Escritura en nftables Fuera de los Límites del kernel de Linux; nft_byteorder administra incorrectamente los contenidos de registro de VM cuando CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red | |
| Modificada | Alta (7.8) | 1.9% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 5/7/2023 | 17/6/2026 | Vulnerabilidad de Escalada de Privilegios Locales de Use-After-Free de Linux nftables; 'nft_chain_lookup_byid()' no pudo comprobar si una cadena estaba activa y CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red | |
| Modificada | Alta (7.5) | 3.0% | — | Djangoproject DjangoDebian LinuxFedoraproject Fedora | 3/7/2023 | 17/6/2026 | In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs. | |
| Modificada | Media (4.3) | 0.46% | — | Menu Swapper Project Menu Swapper | 1/7/2023 | 17/6/2026 | The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0.2. This is due to missing or incorrect nonce validation on the mswp_save_meta() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they… | |
| Modificada | Alta (7.5) | 3.9% | — | Nodejs Node.jsFedoraproject Fedora | 30/6/2023 | 8/10/2026 | The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence… | |
| Modificada | Media (5.7) | 0.55% | 💥 PoC | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 30/6/2023 | 17/6/2026 | A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%. | |
| Modificada | Media (6.1) | 0.36% | — | Pacparser Project Pacparser | 30/6/2023 | 17/6/2026 | pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products). | |
| Modificada | Crítica (9.8) | 0.95% | — | Play With Docker Project Play With Docker | 29/6/2023 | 17/6/2026 | Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape. | |
| Modificada | Crítica (9.8) | 0.75% | — | Property Cloud Platform Management Center Project Property Cloud Platform Management Center | 29/6/2023 | 17/6/2026 | Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection. | |
| Modificada | Media (6.1) | 0.39% | — | Meldekarten Generator Project Meldekarten Generator | 27/6/2023 | 17/6/2026 | Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user input isn't (fully) sanitized after… | |
| Modificada | Crítica (10) | 0.87% | — | PlantumlFedoraproject Fedora | 27/6/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. | |
| Modificada | Media (5.3) | 0.87% | — | PlantumlFedoraproject Fedora | 27/6/2023 | 17/6/2026 | Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. | |
| Modificada | Media (4.8) | 0.44% | — | Codecolorer Project Codecolorer | 27/6/2023 | 17/6/2026 | The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.44% | — | Editorial Calendar Project Editorial Calendar | 27/6/2023 | 17/6/2026 | The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users. | |
| Modificada | Alta (7.8) | 3.9% | 💥 PoC | Artifex GhostscriptDebian LinuxFedoraproject Fedora | 25/6/2023 | 28/8/2026 | Artifex Ghostscript a través de 10.01.2 maneja mal la validación de permisos para dispositivos pipe (con el prefijo %pipe% o el prefijo | pipe character). | |
| Modificada | Media (4.4) | 0.26% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+5 | 23/6/2023 | 17/6/2026 | A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic. |