Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.5)0.50%—Ikus-soft Rdiffweb22/9/202217/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.
ModificadaMedia (4.3)0.39%—Ikus-soft Rdiffweb22/9/202217/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
ModificadaMedia (4.3)0.39%—Ikus-soft Rdiffweb21/9/202217/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
ModificadaMedia (5.3)0.55%—Ikus-soft Rdiffweb21/9/202217/6/2026
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.
ModificadaMedia (4.3)0.40%—Ikus-soft Rdiffweb17/9/202217/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.
ModificadaAlta (8.8)0.76%—Ikus-soft Rdiffweb15/9/202217/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.
ModificadaAlta (8.8)0.98%—Ikus-soft Rdiffweb13/9/202217/6/2026
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.
ModificadaMedia (5.3)0.87%—Ikus-soft Rdiffweb13/9/202217/6/2026
Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.
ModificadaAlta (7.5)0.71%—Ikus-soft Rdiffweb13/9/202217/6/2026
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2.
ModificadaAlta (8.8)2.5%—Diffplug Goomph11/9/202217/6/2026
This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an attacker to achieve remote code execution…
ModificadaAlta (8.8)1.2%—Ikus-soft Rdiffweb8/9/202217/6/2026
Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.
ModificadaCrítica (9.8)1.8%—Diffy Project Diffy23/6/202217/6/2026
The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.
ModificadaAlta (7.5)1.1%—Rdiff Project Rdiff27/12/202117/6/2026
An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.
ModificadaAlta (7.8)0.21%—Google Bindiff29/6/202117/6/2026
An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. This can allow the attacker to control the instruction pointer and execute arbitrary code. It is recommended to upgrade BinDiff 7
ModificadaCrítica (9.8)2.6%—Daemonology Bsdiff16/9/202017/6/2026
A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
ModificadaAlta (7.8)1.1%—Pypi Bsdiff422/7/202017/6/2026
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.
ModificadaCrítica (9.8)2.1%—Git-diff-apply Project Git-diff-apply7/1/202017/6/2026
In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.
ModificadaMedia (5.9)0.72%—Diffplug Eclipse-cdtDiffplug Eclipse-groovyDiffplug Eclipse-wtp5/9/201917/6/2026
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have…
ModificadaAlta (7.5)1.5%—Diffplug GradleDiffplug Maven28/6/201917/6/2026
In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a…
ModificadaMedia (4.6)0.30%—Rediffmail9/5/201917/6/2026
The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persisting after a logout.
ModificadaAlta (8.1)0.58%—Node-bsdiff-android Project Node-bsdiff-android4/6/201817/6/2026
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
ModificadaCrítica (9.8)2.2%—Reproducible Builds DiffoscopeDebian Linux13/4/201817/6/2026
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
ModificadaBaja (3.3)0.37%—Debian LinuxTardiff Project Tardiff6/5/201617/6/2026
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
ModificadaCrítica (9.8)5.4%—Tardiff Project TardiffDebian Linux6/5/201617/6/2026
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
ModificadaAlta (9.3)2.1%—Threediffy Threedify Designer1/1/201516/6/2026
The cmdSave method in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allows remote attackers to write to arbitrary files via a pathname in the argument.