Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

6915 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)1.4%—Openprinting CupsFedoraproject FedoraDebian LinuxApple Macos22/6/202317/6/2026
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is…
ModificadaBaja (2.7)0.68%—Flask-appbuilder Project Flask-appbuilder22/6/202317/6/2026
Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User forms trigger a database error, this error is surfaced back to this actor on the UI. On certain…
ModificadaMedia (4.8)0.39%—Smoothscroller Project Smoothscroller22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Neil Gee Smoothscroller plugin <= 1.0.0 versions.
ModificadaMedia (4.8)0.37%—Vigilantor Project Vigilantor22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Drew Phillips VigilanTor plugin <= 1.3.10 versions.
ModificadaMedia (6.1)0.38%—Tags Cloud Manager Project Tags Cloud Manager22/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aakif Kadiwala Tags Cloud Manager plugin <= 1.0.0 versions.
ModificadaAlta (7.5)2.5%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33…
ModificadaAlta (7.5)3.6%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of…
ModificadaAlta (8.8)0.25%—Zephyr Project Manager Project Zephyr Project Manager19/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.
ModificadaMedia (4.8)0.47%—Artprojectgroup Custom Base Terms19/6/202317/6/2026
The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.44%—Responsive Tabs FOR Wpbakery Page Builder Project Responsive Tabs FOR Wpbakery Page Builder19/6/202317/6/2026
The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored…
ModificadaMedia (5.5)0.50%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.35%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.37%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (4.8)0.37%—Asmember Project Asmember16/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Suess asMember plugin <= 1.5.4 versions.
ModificadaMedia (5.5)0.26%—KubernetesFedoraproject Fedora16/6/202317/6/2026
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This…
ModificadaAlta (7.5)1.0%—Htmlcleaner Project Htmlcleaner14/6/202317/6/2026
An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaAlta (7.5)2.0%—Apache Traffic ServerDebian LinuxFedoraproject Fedora14/6/202317/6/2026
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through…
ModificadaAlta (8.8)13%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.94%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)14%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.94%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaBaja (3.9)14%⚠ Explotación activaVmware ToolsDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada.
ModificadaMedia (5.5)0.20%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux12/6/202317/6/2026
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
ModificadaMedia (6.5)0.72%—Doorkeeper Project Doorkeeper12/6/202317/6/2026
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This…
ModificadaMedia (4.8)0.37%—UTM Tracker Project UTM Tracker12/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ludwig Media UTM Tracker plugin <= 1.3.1 versions.