Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.50% | — | Ikus-soft Rdiffweb | 22/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7. | |
| Modificada | Media (4.3) | 0.39% | — | Ikus-soft Rdiffweb | 22/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6. | |
| Modificada | Media (4.3) | 0.39% | — | Ikus-soft Rdiffweb | 21/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6. | |
| Modificada | Media (5.3) | 0.55% | — | Ikus-soft Rdiffweb | 21/9/2022 | 17/6/2026 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6. | |
| Modificada | Media (4.3) | 0.40% | — | Ikus-soft Rdiffweb | 17/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5. | |
| Modificada | Alta (8.8) | 0.76% | — | Ikus-soft Rdiffweb | 15/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3. | |
| Modificada | Alta (8.8) | 0.98% | — | Ikus-soft Rdiffweb | 13/9/2022 | 17/6/2026 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2. | |
| Modificada | Media (5.3) | 0.87% | — | Ikus-soft Rdiffweb | 13/9/2022 | 17/6/2026 | Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2. | |
| Modificada | Alta (7.5) | 0.71% | — | Ikus-soft Rdiffweb | 13/9/2022 | 17/6/2026 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.2. | |
| Modificada | Alta (8.8) | 2.5% | — | Diffplug Goomph | 11/9/2022 | 17/6/2026 | This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an attacker to achieve remote code execution… | |
| Modificada | Alta (8.8) | 1.2% | — | Ikus-soft Rdiffweb | 8/9/2022 | 17/6/2026 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1. | |
| Modificada | Crítica (9.8) | 1.8% | — | Diffy Project Diffy | 23/6/2022 | 17/6/2026 | The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string. | |
| Modificada | Alta (7.5) | 1.1% | — | Rdiff Project Rdiff | 27/12/2021 | 17/6/2026 | An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations. | |
| Modificada | Alta (7.8) | 0.21% | — | Google Bindiff | 29/6/2021 | 17/6/2026 | An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. This can allow the attacker to control the instruction pointer and execute arbitrary code. It is recommended to upgrade BinDiff 7 | |
| Modificada | Crítica (9.8) | 2.6% | — | Daemonology Bsdiff | 16/9/2020 | 17/6/2026 | A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries. | |
| Modificada | Alta (7.8) | 1.1% | — | Pypi Bsdiff4 | 22/7/2020 | 17/6/2026 | A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file. | |
| Modificada | Crítica (9.8) | 2.1% | — | Git-diff-apply Project Git-diff-apply | 7/1/2020 | 17/6/2026 | In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2. | |
| Modificada | Media (5.9) | 0.72% | — | Diffplug Eclipse-cdtDiffplug Eclipse-groovyDiffplug Eclipse-wtp | 5/9/2019 | 17/6/2026 | In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have… | |
| Modificada | Alta (7.5) | 1.5% | — | Diffplug GradleDiffplug Maven | 28/6/2019 | 17/6/2026 | In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a… | |
| Modificada | Media (4.6) | 0.30% | — | Rediffmail | 9/5/2019 | 17/6/2026 | The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persisting after a logout. | |
| Modificada | Alta (8.1) | 0.58% | — | Node-bsdiff-android Project Node-bsdiff-android | 4/6/2018 | 17/6/2026 | node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks. | |
| Modificada | Crítica (9.8) | 2.2% | — | Reproducible Builds DiffoscopeDebian Linux | 13/4/2018 | 17/6/2026 | diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. | |
| Modificada | Baja (3.3) | 0.37% | — | Debian LinuxTardiff Project Tardiff | 6/5/2016 | 17/6/2026 | Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory. | |
| Modificada | Crítica (9.8) | 5.4% | — | Tardiff Project TardiffDebian Linux | 6/5/2016 | 17/6/2026 | Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file. | |
| Modificada | Alta (9.3) | 2.1% | — | Threediffy Threedify Designer | 1/1/2015 | 16/6/2026 | The cmdSave method in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allows remote attackers to write to arbitrary files via a pathname in the argument. |