Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

6915 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.39%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
ModificadaAlta (7.8)0.27%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
ModificadaMedia (5.5)0.28%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
ModificadaMedia (5.5)0.21%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
ModificadaAlta (8.8)0.33%—WP Dummy Content Generator Project WP Dummy Content Generator10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions.
ModificadaAlta (8.8)0.33%—Webwinkelkeur Project Webwinkelkeur10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Albert Peschar WebwinkelKeur plugin <= 3.24 versions.
ModificadaMedia (4.8)0.54%—Image Protector Project Image Protector10/7/202317/6/2026
The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (5.5)65%—LibreofficeFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
ModificadaAlta (8.2)1.0%—Youtube-dlc Project Youtube-dlcYt-dl Youtube-dlYt-dlp Project Yt-dlpFedoraproject Fedora6/7/202317/6/2026
yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them when the host for download fragments differs from their parent manifest's host. This vulnerable…
ModificadaAlta (7.8)1.5%💥 PoCLinux KernelDebian LinuxFedoraproject FedoraNetapp H300s+45/7/202317/6/2026
Vulnerabilidad de Lectura/Escritura en nftables Fuera de los Límites del kernel de Linux; nft_byteorder administra incorrectamente los contenidos de registro de VM cuando CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red
ModificadaAlta (7.8)1.9%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux5/7/202317/6/2026
Vulnerabilidad de Escalada de Privilegios Locales de Use-After-Free de Linux nftables; 'nft_chain_lookup_byid()' no pudo comprobar si una cadena estaba activa y CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red
ModificadaAlta (7.5)3.0%—Djangoproject DjangoDebian LinuxFedoraproject Fedora3/7/202317/6/2026
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
ModificadaMedia (4.3)0.46%—Menu Swapper Project Menu Swapper1/7/202317/6/2026
The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0.2. This is due to missing or incorrect nonce validation on the mswp_save_meta() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they…
ModificadaAlta (7.5)3.9%—Nodejs Node.jsFedoraproject Fedora30/6/20238/10/2026
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence…
ModificadaMedia (5.7)0.55%💥 PoCLinux KernelRedhat Enterprise LinuxFedoraproject Fedora30/6/202317/6/2026
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.
ModificadaMedia (6.1)0.36%—Pacparser Project Pacparser30/6/202317/6/2026
pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).
ModificadaCrítica (9.8)0.95%—Play With Docker Project Play With Docker29/6/202317/6/2026
Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.
ModificadaCrítica (9.8)0.75%—Property Cloud Platform Management Center Project Property Cloud Platform Management Center29/6/202317/6/2026
Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
ModificadaMedia (6.1)0.39%—Meldekarten Generator Project Meldekarten Generator27/6/202317/6/2026
Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user input isn't (fully) sanitized after…
ModificadaCrítica (10)0.87%—PlantumlFedoraproject Fedora27/6/202317/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
ModificadaMedia (5.3)0.87%—PlantumlFedoraproject Fedora27/6/202317/6/2026
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
ModificadaMedia (4.8)0.44%—Codecolorer Project Codecolorer27/6/202317/6/2026
The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.44%—Editorial Calendar Project Editorial Calendar27/6/202317/6/2026
The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users.
ModificadaAlta (7.8)3.9%💥 PoCArtifex GhostscriptDebian LinuxFedoraproject Fedora25/6/202328/8/2026
Artifex Ghostscript a través de 10.01.2 maneja mal la validación de permisos para dispositivos pipe (con el prefijo %pipe% o el prefijo | pipe character).
ModificadaMedia (4.4)0.26%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+523/6/202317/6/2026
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.