Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.7%—Trusteddomain OpendmarcFedoraproject FedoraDebian Linux27/7/202017/6/2026
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap…
ModificadaMedia (5.3)2.2%—Trusteddomain OpendmarcFedoraproject Fedora27/4/202017/6/2026
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.
ModificadaCrítica (9.8)2.6%—Trusteddomain OpendmarcPypolicyd-spf Project Pypolicyd-spfFedoraproject Fedora27/4/202017/6/2026
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
ModificadaCrítica (9.8)2.3%—Marchnetworks Command Client1/4/202017/6/2026
The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.
ModificadaAlta (7.5)1.5%—Modoboa-dmarc10/12/201917/6/2026
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the /dev/random file within XML documents that are…
ModificadaCrítica (9.8)2.5%—Trusteddomain OpendmarcDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux17/9/201917/6/2026
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.
ModificadaAlta (7.5)1.0%—Marcelominingtoken Project Marcelominingtoken9/7/201817/6/2026
The mint function of a smart contract implementation for MiningToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.8)1.8%—March-hare Wincvs5/2/201817/6/2026
March Hare WINCVS before 2.8.01 build 6610, and CVS Suite before 2009R2 build 6610, contains an Insecure Library Loading vulnerability in the wincvs2.exe or wincvs.exe file, which may allow local users to gain privileges via a Trojan horse Python or TCL DLL file in the current working directory.
ModificadaCrítica (9.8)47%💥 PoCRibboncommunications Edgemarc Firmware16/5/201717/6/2026
The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application:…
ModificadaMedia (5.4)0.27%—Automon Marcus Butler Unofficial20/10/201417/6/2026
The Marcus Butler Unofficial (aka com.automon.ay.marcus.butler) application 1.4.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.6)4.1%—Marc Lehmann Rxvt-unicode14/5/201417/6/2026
rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
ModificadaBaja (2.6)2.1%—Marcel Brinkkemper Lazyest-gallery11/4/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)1.6%—Galen Charlton Marc-xml26/1/201417/6/2026
XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.
ModificadaMedia (4.6)0.36%—Marc Deslauriers Software-propertiesCanonical Ubuntu Linux3/10/201316/6/2026
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race…
ModificadaBaja (3.3)0.34%—Debian Txt2manMarc Vertes Txt2man30/9/201316/6/2026
A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.
ModificadaMedia (4.3)2.2%—Marcel Brinkkemper Lazyest-backup12/2/201316/6/2026
Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xml_or_all parameter.
ModificadaBaja (2.1)0.96%—Marc Ingram Services26/12/201216/6/2026
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."
ModificadaAlta (10)2.1%—Marco Hezel HM Tinymarket7/10/201116/6/2026
Unspecified vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)1.0%—Marco Hezel HM Tinymarket7/10/201116/6/2026
SQL injection vulnerability in the Tiny Market (hm_tinymarket) extension 0.5.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.
ModificadaAlta (7.5)1.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files.
Orbitaley — Vulnerabilidades