Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.3% | — | Opensuse Obs-service-source Validator | 1/3/2018 | 17/6/2026 | A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs. | |
| Modificada | Alta (7) | 0.48% | — | Redhat Hibernate ValidatorRedhat SatelliteRedhat Satellite CapsuleRedhat Jboss Enterprise Application Platform+2 | 10/1/2018 | 17/6/2026 | In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access… | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The ReadData function in ebmlstring.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.2% | — | Matroska Mkvalidator | 10/11/2017 | 17/6/2026 | The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Kabona Webdatorcentral | 7/11/2017 | 17/6/2026 | A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.0. WDC stores password credentials in plaintext. | |
| Modificada | Media (6.1) | 1.1% | — | Kabona AB Webdatorcentral | 13/2/2017 | 17/6/2026 | An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. This non-validated redirect/non-validated forward (OPEN REDIRECT) allows chaining with authenticated vulnerabilities. | |
| Modificada | Alta (8.2) | 1.1% | — | Kabona AB Webdatorcentral | 13/2/2017 | 17/6/2026 | An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. The web server URL inputs are not sanitized correctly, which may allow cross-site scripting vulnerabilities. | |
| Modificada | Crítica (9.8) | 2.3% | — | Kabona AB Webdatorcentral | 13/2/2017 | 17/6/2026 | An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. WDC does not limit authentication attempts that may allow a brute force attack method. | |
| Modificada | Media (5.4) | 0.27% | — | Redatoms Three | 16/10/2014 | 17/6/2026 | The RedAtoms Three (aka com.redatoms.mojodroid.tw.gp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 2.9% | — | Redhat Hibernate Validator | 30/9/2014 | 17/6/2026 | ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application. | |
| Modificada | Alta (7.8) | 1.7% | — | Broadcom Erwin Data Model Validator | 11/7/2007 | 16/6/2026 | CA ERwin Data Model Validator (formerly AllFusion Data Model Validator) allows remote attackers to (1) cause a denial of service (application hang) via a malformed .EXP database file and (2) cause a denial of service (aaplication crash) via a crafted .EXP database file, which triggers a NULL dereference. | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Monolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions NO ONE Lives ForeverMonolith Productions Shogo | 31/12/2004 | 16/6/2026 | Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query. |