Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.45% | — | GNU SED | 25/6/2026 | 27/6/2026 | Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation. | |
| Aplazada | Crítica (9.8) | 0.82% | — | Signup SigninAI | 24/6/2026 | 29/6/2026 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore… | |
| Pendiente de análisis | Baja (2.9) | 0.15% | — | GnupgAI | 23/6/2026 | 25/6/2026 | CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182. | |
| Analizada | Baja (2.5) | 0.14% | — | GNU Libidn | 23/6/2026 | 29/6/2026 | GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. | |
| Modificada | Media (5.3) | 0.41% | — | GNU SaslDebian Linux | 23/6/2026 | 31/7/2026 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server. | |
| Aplazada | Baja (3.7) | 0.40% | — | GNU SavaneAI | 20/6/2026 | 22/6/2026 | GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization. | |
| Aplazada | Media (5.3) | 0.21% | — | GNU TARAIUbuntuAIDebianAICentosAI | 17/6/2026 | 22/6/2026 | The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extraction path traversal was… | |
| Pendiente de análisis | Media (6.6) | 0.20% | — | GnutlsAI | 16/6/2026 | 2/10/2026 | A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path. | |
| Aplazada | Alta (8.8) | 0.27% | — | WOW Viral SignupsAI | 9/6/2026 | 21/7/2026 | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup'… | |
| Pendiente de análisis | Baja (3.7) | 0.63% | — | GnutlsAI | 1/6/2026 | 2/10/2026 | A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information… | |
| Pendiente de análisis | Media (4.3) | 0.18% | — | Gnome Glib-networkingAIGnutlsAI | 28/5/2026 | 21/7/2026 | A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships,… | |
| Aplazada | Media (5.5) | 0.57% | — | GNU LibredwgAI | 27/5/2026 | 24/7/2026 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name:… | |
| Pendiente de análisis | Alta (8.2) | 0.95% | — | GnutlsAI | 26/5/2026 | 2/10/2026 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure. | |
| Pendiente de análisis | Media (5.3) | 0.92% | — | GnutlsAI | 26/5/2026 | 2/10/2026 | A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or… | |
| Pendiente de análisis | Alta (8.2) | 0.56% | — | GnutlsAI | 26/5/2026 | 2/10/2026 | A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or… | |
| Pendiente de análisis | Alta (7.1) | 0.49% | — | GnutlsAI | 26/5/2026 | 2/10/2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS… | |
| Aplazada | Baja (1.9) | 0.16% | — | GNU LibredwgAI | 26/5/2026 | 23/7/2026 | A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgbmp Utility. Executing a manipulation can lead to out-of-bounds read. The attack requires local access. The exploit has been made available to the… | |
| Aplazada | Baja (1.9) | 0.16% | — | GNU LibredwgAI | 26/5/2026 | 23/7/2026 | A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been released to the… | |
| Aplazada | Baja (1.9) | 0.16% | — | GNU LibredwgAI | 25/5/2026 | 23/7/2026 | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used… | |
| Aplazada | Baja (1.9) | 0.16% | — | GNU LibredwgAI | 25/5/2026 | 23/7/2026 | A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and… | |
| Aplazada | Baja (1.9) | 0.17% | — | GNU LibredwgAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The… | |
| Aplazada | Baja (1.9) | 0.16% | — | GNU LibredwgAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly… | |
| Aplazada | Baja (1.9) | 0.17% | — | GNU LibredwgAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made… | |
| Aplazada | Alta (7.5) | 0.63% | — | GNU SaslAI | 24/5/2026 | 23/7/2026 | In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c. | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 2/10/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… |