Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
6915 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 52% | — | Git-scm GITFedoraproject Fedora | 25/4/2023 | 17/6/2026 | Git es un sistema de control de revisiones. Antes de las versiones 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3 y 2.40.1, mediante alimentación entrada especialmente manipulada para `git apply --reject`, una ruta fuera del árbol de trabajo se puede sobrescribir con contenidos… | |
| Modificada | Media (4.8) | 0.39% | — | Link Juice Keeper Project Link Juice Keeper | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in George Pattihis Link Juice Keeper plugin <= 2.0.2 versions. | |
| Modificada | Media (4.4) | 0.22% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+4 | 25/4/2023 | 8/10/2026 | A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. | |
| Modificada | Alta (7.8) | 0.26% | — | XENFedoraproject Fedora | 25/4/2023 | 17/6/2026 | x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for… | |
| Modificada | Media (6.5) | 0.97% | — | Getlaminas Laminas-diactorosGuzzlephp Psr-7Fedoraproject Fedora | 24/4/2023 | 17/6/2026 | Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a header key or value, can cause an invalid… | |
| Modificada | Media (4.8) | 0.23% | — | Custom Post Type AND Taxonomy GUI Manager Project Custom Post Type AND Taxonomy GUI Manager | 24/4/2023 | 17/6/2026 | The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF | |
| Modificada | Media (5.5) | 0.41% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware | 24/4/2023 | 17/6/2026 | An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem)… | |
| Modificada | Media (5.4) | 0.36% | — | Ultimate WP Query Search Filter Project Ultimate WP Query Search Filter | 23/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Simple PDF Viewer Project Simple PDF Viewer | 23/4/2023 | 17/6/2026 | Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions. | |
| Modificada | Media (6.1) | 0.41% | — | User Meta Manager Project User Meta Manager | 23/4/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Jason Lau User Meta Manager plugin <= 3.4.9 versions. | |
| Modificada | Media (4.8) | 0.39% | — | 0MK Shortener Project 0MK Shortener | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Boris Kuzmanov 0mk Shortener plugin <= 0.2 versions. | |
| Modificada | Media (6.7) | 0.24% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 20/4/2023 | 17/6/2026 | An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash… | |
| Modificada | Media (6.1) | 0.51% | — | Eslint-detailed-reporter Project Eslint-detailed-reporter | 20/4/2023 | 17/6/2026 | A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by this issue is the function renderIssue in the library lib/template-generator.js. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The patch… | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 5.7% | ⚠ Explotación activa | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.0% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeDebian LinuxFedoraproject Fedora | 19/4/2023 | 17/6/2026 | Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (5.3) | 2.5% | — | Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython | 19/4/2023 | 17/6/2026 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after… | |
| Modificada | Media (6.5) | 1.3% | — | RedisDebian LinuxFedoraproject Fedora | 18/4/2023 | 17/6/2026 | Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Components Services). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Partition). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Media (4.9) | 1.5% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Partition). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Media (4.4) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Components Services). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los… | |
| Modificada | Media (6.5) | 1.5% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/4/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Optimizer). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con pocos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… |