Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

6917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.72%—Editorial Calendar Project Editorial Calendar8/4/202316/6/2026
A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched…
ModificadaCrítica (9.8)0.90%—Cdesigner Project Cdesigner7/4/202317/6/2026
Se ha descubierto que Prestashop cdesigner v3.1.3 a v3.1.8 contiene una vulnerabilidad de inyección de código en el componente CdesignerSaverotateModuleFrontController::initContent().
ModificadaMedia (4.8)0.44%—Zeno Font Resizer Project Zeno Font Resizer7/4/202317/6/2026
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Marcel Pol Zeno Font Resizer plugin <= 1.7.9 versions.
ModificadaMedia (4.8)0.39%—Auto Hide Admin BAR Project Auto Hide Admin BAR7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcel Bootsman Auto Hide Admin Bar plugin <= 1.6.1 versions.
ModificadaMedia (6.5)0.95%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (6.5)0.98%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (6.5)0.91%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
ModificadaAlta (8.8)0.97%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.88%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.88%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.97%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.91%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.91%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.95%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.76%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.94%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.97%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.1%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (5.5)0.19%—Edb-debugger Project Edb-debugger4/4/202317/6/2026
An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.
ModificadaMedia (5.3)0.99%—Cesnet LibyangFedoraproject Fedora3/4/202317/6/2026
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.
ModificadaMedia (6.3)0.24%—Fedoraproject FedoraLinux Kernel3/4/202317/6/2026
A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea
ModificadaAlta (7.5)1.6%—FrroutingFedoraproject FedoraDebian Linux3/4/202317/6/2026
Se encontró una afirmación accesible en Frrouting frr-bgpd 8.3.0 en la función peek_for_as4_capability. Los atacantes pueden construir maliciosamente paquetes abiertos BGP y enviarlos a pares BGP que ejecutan frr-bgpd, lo que resulta en DoS.
ModificadaMedia (5.4)0.47%—Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder3/4/202317/6/2026
The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaCrítica (9.8)1.2%—MediawikiFedoraproject Fedora31/3/202317/6/2026
An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
ModificadaMedia (6.1)0.55%—Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator31/3/202317/6/2026
A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affected by this issue is the function get_scale of the file Master.php. The manipulation of the argument perc leads to cross site scripting. The attack may be launched remotely. The exploit has been…