Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.38% | — | KDE Ktexteditor | 25/4/2018 | 17/6/2026 | An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an… | |
| Modificada | Media (6.8) | 0.78% | 💥 PoC | KDE Plasma-workspaceDebian Linux | 7/2/2018 | 17/6/2026 | An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution.… | |
| Modificada | Media (5.3) | 2.1% | — | KDE Plasma-workspace | 7/2/2018 | 17/6/2026 | An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element. | |
| Modificada | Media (5.9) | 1.2% | — | KDE Kmail | 28/9/2017 | 17/6/2026 | KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (7) | 0.24% | — | Artsproject ArtsKdelibs | 25/7/2017 | 17/6/2026 | aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory. | |
| Modificada | Alta (7.5) | 1.3% | — | KDE KmailKDE Messagelib | 13/6/2017 | 17/6/2026 | KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (7.8) | 1.8% | 💥 Exploit | KDE KauthKdelibs | 17/5/2017 | 17/6/2026 | KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app. | |
| Modificada | Alta (7.8) | 3.1% | — | Fedoraproject FedoraKDE ARK | 27/3/2017 | 17/6/2026 | ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications. | |
| Modificada | Media (5.5) | 0.86% | — | KdelibsKDE KIO | 2/3/2017 | 17/6/2026 | kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file. | |
| Modificada | Media (6.5) | 1.2% | — | KDE Kmail | 23/12/2016 | 17/6/2026 | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed. | |
| Modificada | Alta (8.1) | 1.9% | — | KDE Kmail | 23/12/2016 | 17/6/2026 | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled. | |
| Modificada | Alta (7.3) | 2.3% | — | KDE KmailDebian LinuxFedoraproject FedoraSuse Linux Enterprise | 23/12/2016 | 17/6/2026 | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is… | |
| Modificada | Media (4.9) | 1.7% | — | Kde-cli-toolsOpensuse LeapOpensuse | 23/12/2016 | 17/6/2026 | A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user. | |
| Modificada | Media (6.8) | 0.44% | — | KDE KscreenlockerKDE Plasma-workspaceFedoraproject FedoraOpensuse Leap | 23/12/2016 | 17/6/2026 | Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again. | |
| Modificada | Alta (7.5) | 4.4% | — | Canonical Ubuntu LinuxKDE Karchives | 2/8/2016 | 17/6/2026 | Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads. | |
| Modificada | Alta (8.4) | 0.40% | — | Opensuse LeapOpensuseKDE Frameworks | 13/7/2016 | 17/6/2026 | kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file. | |
| Modificada | Media (4.3) | 1.2% | — | Entitybulkdelete Project Entitybulkdelete | 15/6/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes. | |
| Modificada | Media (4.3) | 1.4% | — | KDE Plasma-workspaceKde-workspace | 26/1/2015 | 17/6/2026 | kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked. | |
| Modificada | Media (4.3) | 1.2% | — | KDE Plasma-workspace | 26/1/2015 | 17/6/2026 | plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package. | |
| Modificada | Media (5) | 2.1% | — | KDE Applications | 18/1/2015 | 17/6/2026 | kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack. | |
| Modificada | Media (4.3) | 2.1% | — | URS Wolfer KwebkitpartKde-runtimeKDE Kio-extrasOpensuse | 8/12/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8)… | |
| Modificada | Alta (7.2) | 0.39% | — | KDE Plasma-desktopKde-workspace | 6/12/2014 | 17/6/2026 | The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument. | |
| Modificada | Media (6.9) | 0.36% | — | Debian Kde4libsCanonical Ubuntu LinuxKDE KauthKdelibs | 19/8/2014 | 17/6/2026 | KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and… | |
| Modificada | Media (4.3) | 0.71% | — | OpensuseKdelibs | 1/7/2014 | 17/6/2026 | kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate. | |
| Modificada | Media (5) | 2.0% | — | Kdelibs | 5/2/2014 | 16/6/2026 | kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message. |