Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
6915 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.69% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 9/6/2023 | 17/6/2026 | Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or… | |
| Modificada | Alta (7.2) | 1.2% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 9/6/2023 | 17/6/2026 | schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code. | |
| Modificada | Media (5.3) | 0.53% | — | GrpcFedoraproject Fedora | 9/6/2023 | 17/6/2026 | gRPC contiene una vulnerabilidad por la que un cliente puede provocar la finalización de la conexión entre un proxy HTTP2 y un servidor gRPC. Un error de codificación en base64 para cabeceras con sufijo "-bin" provocará la desconexión por parte del servidor gRPC, pero suele estar permitido por los proxies HTTP2. Se… | |
| Modificada | Media (4.3) | 0.57% | — | Ooohboi Steroids FOR Elementor Project Ooohboi Steroids FOR Elementor | 9/6/2023 | 17/6/2026 | The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site. | |
| Modificada | Crítica (9.8) | 1.7% | — | Golang GOFedoraproject Fedora | 8/6/2023 | 17/6/2026 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. Flags containing embedded spaces are… | |
| Modificada | Crítica (9.8) | 1.8% | — | Golang GOFedoraproject Fedora | 8/6/2023 | 17/6/2026 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. The arguments for a number of flags… | |
| Modificada | Alta (7.8) | 0.43% | — | Golang GOFedoraproject Fedora | 8/6/2023 | 17/6/2026 | En las plataformas Unix, el entorno de ejecución de Go no se comporta de forma diferente cuando se ejecuta un binario con los bits setuid/setgid. Esto puede ser peligroso en ciertos casos, como cuando se vuelca el estado de la memoria o se asume el estado de los descriptores de archivos de E/S estándar. Si se ejecuta… | |
| Modificada | Crítica (9.8) | 1.7% | — | Golang GOFedoraproject Fedora | 8/6/2023 | 17/6/2026 | The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command,… | |
| Modificada | Media (6.5) | 1.4% | — | Freedesktop DbusFedoraproject FedoraDebian Linux | 8/6/2023 | 17/6/2026 | D-Bus en versiones anteriores a v1.15.6 a veces permite a usuarios sin privilegios bloquear el "dbus-daemon". Si un usuario privilegiado con control sobre "dbus-daemon" está usando la interfaz "org.freedesktop.DBus.Monitoring" para monitorizar el tráfico del bus de mensajes, entonces un usuario sin privilegios con la… | |
| Modificada | Alta (7.8) | 0.58% | 💥 PoC | Libcap Project LibcapRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 6/6/2023 | 17/6/2026 | A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB. | |
| Modificada | Baja (3.3) | 0.35% | — | Libcap Project LibcapRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora | 6/6/2023 | 17/6/2026 | A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory. | |
| Modificada | Alta (8.8) | 0.35% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above. Users unable to upgrade… | |
| Modificada | Media (6.5) | 0.48% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation verify command on the same machine. The problem has been fixed in… | |
| Modificada | Media (5.7) | 0.51% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation inspect command on the same machine. The problem has been fixed… | |
| Modificada | Media (6.5) | 1.1% | — | Yajl Project YajlFedoraproject FedoraDebian Linux | 6/6/2023 | 17/6/2026 | There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash. | |
| Modificada | Alta (7.5) | 0.90% | — | Arborator Server Project Arborator Server | 6/6/2023 | 17/6/2026 | Esta vulnerabilidad afecta a la función de inicio del archivo project.cgi de Arborator Server. La manipulación de los argumentos del archivo project provoca una denegación de servicio. Este producto utiliza un ciclo de actualizaciones continua, por lo tanto no hay detalles de la versión afectada ni actualizadas. El… | |
| Analizada | Alta (8.8) | 32% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraDebian LinuxCouchbase Server | 5/6/2023 | 8/10/2026 | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.3) | 0.74% | — | Debian LinuxFedoraproject FedoraQT | 5/6/2023 | 17/6/2026 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. | |
| Modificada | Media (6.1) | 0.55% | — | Eelv Newsletter Project Eelv Newsletter | 4/6/2023 | 16/6/2026 | A vulnerability was found in EELV Newsletter Plugin 2.x on WordPress. It has been rated as problematic. Affected by this issue is the function style_newsletter of the file lettreinfo.php. The manipulation of the argument email leads to cross site scripting. The attack may be launched remotely. The name of the patch is… | |
| Modificada | Media (5.5) | 0.37% | — | Bt21 X BTS Wallpaper Project Bt21 X BTS Wallpaper | 2/6/2023 | 9/7/2026 | La aplicación BT21 x BTS Wallpaper v12 para Android permite que aplicaciones no autorizadas soliciten activamente permisos para insertar datos en la base de datos que registra información sobre las preferencias personales de un usuario y que se cargará en la memoria para ser leída y utilizada cuando se abra la… | |
| Modificada | Alta (7.8) | 0.37% | — | Bt21 X BTS Wallpaper Project Bt21 X BTS Wallpaper | 2/6/2023 | 9/7/2026 | The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an… | |
| Modificada | Alta (7.5) | 0.84% | — | Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper | 1/6/2023 | 17/6/2026 | The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data,… | |
| Modificada | Crítica (9.1) | 0.78% | — | Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper | 1/6/2023 | 17/6/2026 | La aplicación Glitter Unicorn Wallpaper para Android 7.0 a 8.0 permite a aplicaciones no autorizadas solicitar activamente permiso para modificar datos en la base de datos que registra información sobre las preferencias personales de un usuario y que se cargará en la memoria para ser leída y utilizada cuando se abra… | |
| Modificada | Alta (7.5) | 1.2% | — | Story Saver FOR Instagram - Video Downloader Project Story Saver FOR Instagram - Video Downloader | 1/6/2023 | 17/6/2026 | Story Saver para Instagram - Vídeo Downloader v1.0.6 para Android tiene un componente expuesto que proporciona un método para modificar el archivo "SharedPreference". Un atacante puede aprovechar este método para inyectar una gran cantidad de datos en cualquier archivo "SharedPreference", que se cargará en la memoria… | |
| Modificada | Alta (8.8) | 0.44% | — | Inline Google Spreadsheet Viewer Project Inline Google Spreadsheet Viewer | 31/5/2023 | 17/6/2026 | A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely.… |