Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
6918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.74% | — | MoodleFedoraproject Fedora | 23/3/2023 | 17/6/2026 | Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access. | |
| Modificada | Crítica (9.8) | 1.2% | — | MoodleFedoraproject Fedora | 23/3/2023 | 17/6/2026 | The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS). | |
| Modificada | Baja (3.3) | 0.23% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 23/3/2023 | 17/6/2026 | A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak. | |
| Modificada | Media (6.5) | 1.8% | — | HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+5 | 23/3/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability. | |
| Modificada | Media (6.3) | 0.31% | — | QemuFedoraproject Fedora | 23/3/2023 | 17/6/2026 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU. | |
| Modificada | Media (5.5) | 0.86% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 23/3/2023 | 17/6/2026 | A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When… | |
| Modificada | Media (6.1) | 0.73% | — | CkeditorFedoraproject Fedora | 22/3/2023 | 17/6/2026 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special conditions: using one of the affected packages on a web page with… | |
| Modificada | Alta (8.8) | 1.3% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.85% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.3% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 3.2% | — | Google ChromeFedoraproject FedoraChromium | 21/3/2023 | 17/6/2026 | Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.82% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.8) | 1.1% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.77% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (6.5) | 0.27% | — | XENDebian LinuxFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would… | |
| Modificada | Alta (8.6) | 1.2% | — | XENDebian LinuxFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would… | |
| Modificada | Alta (7.8) | 0.27% | — | XENDebian LinuxFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data… | |
| Modificada | Media (5.5) | 0.27% | — | XENFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative… | |
| Modificada | Media (6.1) | 0.41% | — | MAP Multi Marker Project MAP Multi Marker | 20/3/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Mickael Austoni Map Multi Marker plugin <= 3.2.1 versions. | |
| Modificada | Crítica (9.8) | 0.87% | — | Simple Music Player Project Simple Music Player | 18/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. Affected is an unknown function of the file save_music.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.4) | 0.39% | — | WP Calendar Project WP Calendar | 17/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3 versions. | |
| Modificada | Alta (7.5) | 8.0% | — | Opener Project Opener | 16/3/2023 | 17/6/2026 | A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP… | |
| Modificada | Crítica (9.8) | 14% | — | Opener Project Opener | 16/3/2023 | 17/6/2026 | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An… | |
| Modificada | Crítica (9.8) | 14% | — | Opener Project Opener | 16/3/2023 | 17/6/2026 | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An… | |
| Modificada | Alta (8.8) | 0.27% | — | MY Calendar Project MY Calendar | 15/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. |