Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
6917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.72% | — | Editorial Calendar Project Editorial Calendar | 8/4/2023 | 16/6/2026 | A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.90% | — | Cdesigner Project Cdesigner | 7/4/2023 | 17/6/2026 | Se ha descubierto que Prestashop cdesigner v3.1.3 a v3.1.8 contiene una vulnerabilidad de inyección de código en el componente CdesignerSaverotateModuleFrontController::initContent(). | |
| Modificada | Media (4.8) | 0.44% | — | Zeno Font Resizer Project Zeno Font Resizer | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Marcel Pol Zeno Font Resizer plugin <= 1.7.9 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Auto Hide Admin BAR Project Auto Hide Admin BAR | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcel Bootsman Auto Hide Admin Bar plugin <= 1.6.1 versions. | |
| Modificada | Media (6.5) | 0.95% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (6.5) | 0.98% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (6.5) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Alta (8.8) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.88% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.88% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.95% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.76% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (5.5) | 0.19% | — | Edb-debugger Project Edb-debugger | 4/4/2023 | 17/6/2026 | An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp. | |
| Modificada | Media (5.3) | 0.99% | — | Cesnet LibyangFedoraproject Fedora | 3/4/2023 | 17/6/2026 | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c. | |
| Modificada | Media (6.3) | 0.24% | — | Fedoraproject FedoraLinux Kernel | 3/4/2023 | 17/6/2026 | A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea | |
| Modificada | Alta (7.5) | 1.6% | — | FrroutingFedoraproject FedoraDebian Linux | 3/4/2023 | 17/6/2026 | Se encontró una afirmación accesible en Frrouting frr-bgpd 8.3.0 en la función peek_for_as4_capability. Los atacantes pueden construir maliciosamente paquetes abiertos BGP y enviarlos a pares BGP que ejecutan frr-bgpd, lo que resulta en DoS. | |
| Modificada | Media (5.4) | 0.47% | — | Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder | 3/4/2023 | 17/6/2026 | The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.8) | 1.2% | — | MediawikiFedoraproject Fedora | 31/3/2023 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header. | |
| Modificada | Media (6.1) | 0.55% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 31/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affected by this issue is the function get_scale of the file Master.php. The manipulation of the argument perc leads to cross site scripting. The attack may be launched remotely. The exploit has been… |