Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

6915 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Story Saver FOR Instagram - Video Downloader Project Story Saver FOR Instagram - Video Downloader31/5/202317/6/2026
Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened.…
ModificadaAlta (7.1)0.26%—Bestweather Project Bestweather31/5/202317/6/2026
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
ModificadaAlta (7.8)0.44%—Bestweather Project Bestweather31/5/202317/6/2026
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulating the database.
ModificadaAlta (7.5)0.55%—Bestweather Project Bestweather30/5/202317/6/2026
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
ModificadaCrítica (9.8)1.2%—Bestweather Project Bestweather30/5/202317/6/2026
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database.
AnalizadaAlta (7.8)3.1%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
ModificadaCrítica (9.8)8.0%💥 PoCImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
AnalizadaMedia (5.5)0.95%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+130/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
ModificadaMedia (5.4)0.36%—Progress BAR Project Progress BAR29/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Reynolds Progress Bar plugin <= 2.2.1 versions.
ModificadaBaja (3.7)2.2%—Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+526/5/202317/6/2026
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which…
ModificadaMedia (5.9)1.8%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+626/5/202317/6/2026
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private…
ModificadaMedia (6.1)3.0%💥 PoCPython RequestsFedoraproject Fedora26/5/202317/6/2026
Requests es una librería HTTP. Desde Requests 2.3.0, Requests ha estado filtrando cabeceras Proxy-Authorization a los servidores de destino cuando se redirige a un endpoint HTTPS. Esto es producto de cómo usamos `rebuild_proxies` para volver a adjuntar la cabecera `Proxy-Authorization` a las peticiones. Para…
ModificadaMedia (6.5)1.1%—LibsshFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,`…
ModificadaAlta (7.8)0.47%—Usebottles BottlesFedoraproject Fedora26/5/202317/6/2026
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
ModificadaMedia (5.5)0.39%—AvahiFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
ModificadaMedia (6.5)1.3%—LibsshFedoraproject FedoraDebian LinuxRedhat Enterprise Linux26/5/202317/6/2026
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
ModificadaAlta (7.5)1.6%—C-ares Project C-aresFedoraproject FedoraDebian Linux25/5/202317/6/2026
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the…
ModificadaMedia (6.5)0.90%—C-ares Project C-aresFedoraproject Fedora25/5/202317/6/2026
c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the random number generator is fed into a…
ModificadaMedia (6.4)0.38%—C-ares Project C-aresFedoraproject FedoraDebian Linux25/5/202317/6/2026
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an…
ModificadaBaja (3.7)0.93%—C-ares Project C-aresFedoraproject Fedora25/5/202317/6/2026
c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not…
ModificadaAlta (8.8)0.26%—Theme Tweaker Project Theme Tweaker23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Manoj Thulasidas Theme Tweaker plugin <= 5.20 versions.
ModificadaAlta (8.8)0.26%—Crayon Syntax Highlighter Project Crayon Syntax Highlighter22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Aram Kocharyan Crayon Syntax Highlighter plugin <= 2.8.4 versions.
ModificadaAlta (8.8)0.27%—MY Calendar Project MY Calendar22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
ModificadaAlta (8.8)0.26%—WP Topbar Project WP Topbar22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Bob Goetz WP-TopBar plugin <= 5.36 versions.
ModificadaAlta (8.8)0.27%—SRS Simple Hits Counter Project SRS Simple Hits Counter22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Atif N SRS Simple Hits Counter plugin <= 1.1.0 versions.