Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.38%—KDE Ktexteditor25/4/201817/6/2026
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an…
ModificadaMedia (6.8)0.78%💥 PoCKDE Plasma-workspaceDebian Linux7/2/201817/6/2026
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution.…
ModificadaMedia (5.3)2.1%—KDE Plasma-workspace7/2/201817/6/2026
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.
ModificadaMedia (5.9)1.2%—KDE Kmail28/9/201717/6/2026
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaAlta (7)0.24%—Artsproject ArtsKdelibs25/7/201717/6/2026
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
ModificadaAlta (7.5)1.3%—KDE KmailKDE Messagelib13/6/201717/6/2026
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaAlta (7.8)1.8%💥 ExploitKDE KauthKdelibs17/5/201717/6/2026
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
ModificadaAlta (7.8)3.1%—Fedoraproject FedoraKDE ARK27/3/201717/6/2026
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
ModificadaMedia (5.5)0.86%—KdelibsKDE KIO2/3/201717/6/2026
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
ModificadaMedia (6.5)1.2%—KDE Kmail23/12/201617/6/2026
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.
ModificadaAlta (8.1)1.9%—KDE Kmail23/12/201617/6/2026
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
ModificadaAlta (7.3)2.3%—KDE KmailDebian LinuxFedoraproject FedoraSuse Linux Enterprise23/12/201617/6/2026
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is…
ModificadaMedia (4.9)1.7%—Kde-cli-toolsOpensuse LeapOpensuse23/12/201617/6/2026
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
ModificadaMedia (6.8)0.44%—KDE KscreenlockerKDE Plasma-workspaceFedoraproject FedoraOpensuse Leap23/12/201617/6/2026
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
ModificadaAlta (7.5)4.4%—Canonical Ubuntu LinuxKDE Karchives2/8/201617/6/2026
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
ModificadaAlta (8.4)0.40%—Opensuse LeapOpensuseKDE Frameworks13/7/201617/6/2026
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.
ModificadaMedia (4.3)1.2%—Entitybulkdelete Project Entitybulkdelete15/6/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes.
ModificadaMedia (4.3)1.4%—KDE Plasma-workspaceKde-workspace26/1/201517/6/2026
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
ModificadaMedia (4.3)1.2%—KDE Plasma-workspace26/1/201517/6/2026
plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.
ModificadaMedia (5)2.1%—KDE Applications18/1/201517/6/2026
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.
ModificadaMedia (4.3)2.1%—URS Wolfer KwebkitpartKde-runtimeKDE Kio-extrasOpensuse8/12/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8)…
ModificadaAlta (7.2)0.39%—KDE Plasma-desktopKde-workspace6/12/201417/6/2026
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
ModificadaMedia (6.9)0.36%—Debian Kde4libsCanonical Ubuntu LinuxKDE KauthKdelibs19/8/201417/6/2026
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and…
ModificadaMedia (4.3)0.71%—OpensuseKdelibs1/7/201417/6/2026
kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.
ModificadaMedia (5)2.0%—Kdelibs5/2/201416/6/2026
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
Orbitaley — Vulnerabilidades