Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
–

6918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.74%—MoodleFedoraproject Fedora23/3/202317/6/2026
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
ModificadaCrítica (9.8)1.2%—MoodleFedoraproject Fedora23/3/202317/6/2026
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
ModificadaBaja (3.3)0.23%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux23/3/202317/6/2026
A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.
ModificadaMedia (6.5)1.8%—HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+523/3/202317/6/2026
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
ModificadaMedia (6.3)0.31%—QemuFedoraproject Fedora23/3/202317/6/2026
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU.
ModificadaMedia (5.5)0.86%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux23/3/202317/6/2026
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When…
ModificadaMedia (6.1)0.73%—CkeditorFedoraproject Fedora22/3/202317/6/2026
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special conditions: using one of the affected packages on a web page with…
ModificadaAlta (8.8)1.3%—Google ChromeFedoraproject Fedora21/3/202317/6/2026
Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.85%—Google ChromeFedoraproject Fedora21/3/202317/6/2026
Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.3%—Google ChromeFedoraproject Fedora21/3/202317/6/2026
Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)3.2%—Google ChromeFedoraproject FedoraChromium21/3/202317/6/2026
Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.82%—Google ChromeFedoraproject Fedora21/3/202317/6/2026
Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.8)1.1%—Google ChromeFedoraproject Fedora21/3/202317/6/2026
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
ModificadaAlta (8.8)0.77%—Google ChromeFedoraproject Fedora21/3/202317/6/2026
Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.5)0.27%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would…
ModificadaAlta (8.6)1.2%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would…
ModificadaAlta (7.8)0.27%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data…
ModificadaMedia (5.5)0.27%—XENFedoraproject Fedora21/3/202317/6/2026
x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative…
ModificadaMedia (6.1)0.41%—MAP Multi Marker Project MAP Multi Marker20/3/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Mickael Austoni Map Multi Marker plugin <= 3.2.1 versions.
ModificadaCrítica (9.8)0.87%—Simple Music Player Project Simple Music Player18/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. Affected is an unknown function of the file save_music.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaMedia (5.4)0.39%—WP Calendar Project WP Calendar17/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3 versions.
ModificadaAlta (7.5)8.0%—Opener Project Opener16/3/202317/6/2026
A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP…
ModificadaCrítica (9.8)14%—Opener Project Opener16/3/202317/6/2026
An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An…
ModificadaCrítica (9.8)14%—Opener Project Opener16/3/202317/6/2026
An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An…
ModificadaAlta (8.8)0.27%—MY Calendar Project MY Calendar15/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.