Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
6918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.28% | — | DH - Anti Adblocker Project DH - Anti Adblocker | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Campaign URL Builder Project Campaign URL Builder | 13/3/2023 | 17/6/2026 | The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.5) | 0.43% | — | VIMFedoraproject Fedora | 7/3/2023 | 17/6/2026 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392. | |
| Modificada | Media (5.5) | 0.27% | — | Vocable Trainer Project Vocable Trainer | 7/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the file src/at/hgz/vocabletrainer/VocableTrainerProvider.java. The manipulation leads to path traversal. Attacking locally is a requirement. Upgrading to version 1.3.1 is able… | |
| Modificada | Alta (8.6) | 1.2% | — | C-ares Project C-aresRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 6/3/2023 | 17/6/2026 | A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity. | |
| Modificada | Media (5.9) | 0.76% | — | SambaFedoraproject Fedora | 6/3/2023 | 17/6/2026 | Se ha encontrado un fallo en samba. Una condición de ejecución en el código de bloqueo de contraseñas puede conllevar el riesgo de que los ataques de fuerza bruta tengan éxito si se cumplen unas condiciones especiales. | |
| Modificada | Media (6.1) | 0.32% | — | Quickentity Editor Project Quickentity Editor | 6/3/2023 | 17/6/2026 | quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name.… | |
| Modificada | Media (5.4) | 0.74% | — | Wpaudio MP3 Player Project Wpaudio MP3 Player | 6/3/2023 | 17/6/2026 | The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.55% | — | Mark User AS Spammer Project Mark User AS Spammer | 6/3/2023 | 17/6/2026 | A vulnerability was found in Mark User as Spammer Plugin 1.0.0/1.0.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function user_row_actions of the file plugin/plugin.php. The manipulation of the argument url leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Media (6.1) | 0.59% | — | Media Downloader Project Media Downloader | 4/3/2023 | 17/6/2026 | A vulnerability was found in Media Downloader Plugin 0.1.992 on WordPress. It has been declared as problematic. This vulnerability affects the function dl_file_resumable of the file getfile.php. The manipulation of the argument file leads to cross site scripting. The attack can be initiated remotely. Upgrading to… | |
| Analizada | Media (6.6) | 0.45% | — | Debian LinuxFedoraproject FedoraNeovimVIM | 4/3/2023 | 18/9/2026 | Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. | |
| Analizada | Media (6.6) | 0.50% | — | Fedoraproject FedoraNeovimVIM | 3/3/2023 | 18/9/2026 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. | |
| Modificada | Media (5.5) | 0.43% | — | Fedoraproject FedoraLibtiff | 3/3/2023 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125. | |
| Modificada | Baja (3.7) | 0.62% | — | PostgresqlFedoraproject FedoraRedhat Integration Camel KRedhat Integration Camel Quarkus+2 | 3/3/2023 | 17/6/2026 | In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes. | |
| Modificada | Media (5.5) | 0.37% | — | Elf-parser Project Elf-parser | 2/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public… | |
| Modificada | Alta (8.8) | 1.1% | — | WebkitgtkFedoraproject Fedora | 2/3/2023 | 17/6/2026 | A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely. | |
| Modificada | Alta (7.8) | 0.46% | — | VIMFedoraproject Fedora | 1/3/2023 | 17/6/2026 | Divide By Zero in GitHub repository vim/vim prior to 9.0.1367. | |
| Modificada | Alta (7.2) | 1.7% | — | Sudo Project SudoFedoraproject Fedora | 28/2/2023 | 17/6/2026 | Sudo before 1.9.13p2 has a double free in the per-command chroot feature. | |
| Modificada | Media (5.5) | 0.31% | — | Golang ImageGolang TiffFedoraproject Fedora | 28/2/2023 | 17/6/2026 | An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service. | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Directory ServerFedoraproject Fedora | 27/2/2023 | 17/6/2026 | A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed… | |
| Modificada | Media (6.1) | 0.48% | — | ADD User Project ADD User | 27/2/2023 | 17/6/2026 | The Custom Add User WordPress plugin through 2.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 1.2% | — | Lite-web-server Project Lite-web-server | 25/2/2023 | 17/6/2026 | All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse. | |
| Modificada | Media (6.5) | 1.7% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp H300s Firmware+5 | 23/2/2023 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain"… | |
| Modificada | Media (5.4) | 0.63% | — | Simple File Downloader Project Simple File Downloader | 21/2/2023 | 17/6/2026 | The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.27% | — | Intuitive Custom Post Order Project Intuitive Custom Post Order | 21/2/2023 | 17/6/2026 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack |