Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
6915 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.37% | — | Baidu-tongji-generator Project Baidu-tongji-generator | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versions. | |
| Modificada | Alta (7.8) | 0.33% | — | Sysstat Project SysstatFedoraproject FedoraDebian Linux | 18/5/2023 | 17/6/2026 | sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377. | |
| Modificada | Media (5.5) | 0.43% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 17/5/2023 | 17/6/2026 | A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service. | |
| Modificada | Crítica (9.8) | 0.76% | — | Cdesigner Project Cdesigner | 17/5/2023 | 17/6/2026 | PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent(). | |
| Modificada | Alta (8.8) | 3.7% | — | Linuxfoundation Cups-filtersFedoraproject FedoraDebian Linux | 17/5/2023 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line… | |
| Modificada | Alta (8.8) | 0.68% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 25% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 29% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 15% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.85% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.87% | — | Google ChromeDebian LinuxFedoraproject Fedora | 16/5/2023 | 17/6/2026 | Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Modificada | Media (5.5) | 0.25% | — | Redhat LibvirtFedoraproject FedoraRedhat Enterprise Linux | 15/5/2023 | 17/6/2026 | A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup. | |
| Analizada | Media (6.5) | 1.3% | — | LibrawFedoraproject FedoraRedhat Enterprise Linux | 15/5/2023 | 17/6/2026 | A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash. | |
| Modificada | Alta (7.2) | 17% | — | AD Inserter Project AD Inserter | 15/5/2023 | 17/6/2026 | The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present | |
| Modificada | Media (4.8) | 0.39% | — | White Label Branding FOR Elementor Page Builder Project White Label Branding FOR Elementor Page Builder | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions. | |
| Modificada | Alta (7.8) | 0.21% | — | Digitalpersona Fpsensor Project Digitalpersona Fpsensor | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-228773… | |
| Modificada | Alta (7.5) | 1.3% | — | Webcamserver Project Webcamserver | 10/5/2023 | 17/6/2026 | Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file. | |
| Modificada | Media (5.4) | 0.36% | — | Bbspoiler Project Bbspoiler | 10/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flector BBSpoiler plugin <= 2.01 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Semalt Blocker Project Semalt Blocker | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss Semalt Blocker plugin <= 1.1.3 versions. | |
| Modificada | Media (5.9) | 0.74% | — | Videolan Dav1dFedoraproject Fedora | 10/5/2023 | 17/6/2026 | VideoLAN dav1d anterior a 1.2.0 tiene una condición de ejecución thread_task.c que puede provocar un bloqueo de la aplicación, relacionado con dav1d_decode_frame_exit. | |
| Modificada | Alta (7.5) | 6.1% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 9/5/2023 | 17/6/2026 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the… | |
| Modificada | Media (5.5) | 0.47% | — | VIMFedoraproject Fedora | 9/5/2023 | 23/6/2026 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531. | |
| Modificada | Alta (7.5) | 2.2% | — | FrroutingDebian LinuxFedoraproject Fedora | 9/5/2023 | 17/6/2026 | Un problema encontrado en Frrouting bgpd v.8.4.2 permite a un atacante remoto causar una denegación de servicio a través de la función bgp_attr_psid_sub(). | |
| Modificada | Media (5.5) | 1.0% | — | FrroutingFedoraproject Fedora | 9/5/2023 | 17/6/2026 | An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function. | |
| Modificada | Alta (7.5) | 1.1% | — | MaradnsFedoraproject FedoraDebian Linux | 9/5/2023 | 17/6/2026 | MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination. The vulnerability… |