Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
5545 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.95% | — | Google ChromeFedoraproject Fedora | 15/5/2024 | 17/6/2026 | Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 15% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject Fedora | 15/5/2024 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 1.0% | — | LibreofficeFedoraproject FedoraDebian Linux | 14/5/2024 | 17/6/2026 | Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted. | |
| Analizada | Alta (7.8) | 1.0% | — | Git-scm GITFedoraproject FedoraDebian Linux | 14/5/2024 | 17/6/2026 | Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those… | |
| Analizada | Alta (7.1) | 1.0% | — | Git-scm GITFedoraproject FedoraDebian Linux | 14/5/2024 | 17/6/2026 | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/`… | |
| Analizada | Baja (3.3) | 0.52% | — | Git-scm GITFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then… | |
| Analizada | Alta (7.8) | 1.4% | 💥 PoC | Git-scm GITFedoraproject FedoraDebian Linux | 14/5/2024 | 17/6/2026 | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1,… | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.5) | 0.40% | — | WiresharkFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Use after free issue in editcap could cause denial of service via crafted capture file | |
| Modificada | Alta (7.5) | 0.81% | — | Fedoraproject FedoraWireshark | 14/5/2024 | 17/6/2026 | MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file | |
| Modificada | Media (5.5) | 0.42% | — | WiresharkFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Memory handling issue in editcap could cause denial of service via crafted capture file | |
| Analizada | Crítica (9.6) | 8.3% | ⚠ Explotación activa | Google ChromeFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.1) | 1.1% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In… | |
| Modificada | Alta (8.8) | 1.8% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in… | |
| Modificada | Alta (7.2) | 2.7% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in… | |
| Modificada | Alta (8) | 13% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from… | |
| Modificada | Alta (8.8) | 26% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code… | |
| Modificada | Media (5.4) | 15% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from… | |
| Modificada | Media (5.4) | 0.84% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in… | |
| Analizada | Media (4.7) | 0.90% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others).… | |
| Modificada | Media (5.5) | 0.60% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 14/5/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. | |
| Modificada | Alta (7.1) | 0.30% | — | Linux KernelDebian LinuxFedoraproject Fedora | 14/5/2024 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head packet exceeds the user_length, packet_buffer_get will now return 0 to… | |
| Modificada | Media (5.5) | 0.24% | — | Linux KernelFedoraproject Fedora | 14/5/2024 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that after the move the old location is simply not available any more. Some… | |
| Analizada | Media (5.5) | 0.30% | — | Linux KernelDebian LinuxFedoraproject Fedora | 14/5/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan->conn will be set to null. But the conn could be… | |
| Modificada | Alta (7.8) | 0.83% | 💥 PoC | Fedoraproject FedoraLinux KernelDebian Linux | 14/5/2024 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated… |