Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.2%—Sane-project Sane BackendsOpensuse LeapCanonical Ubuntu Linux24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
ModificadaMedia (4.3)1.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
ModificadaMedia (4.3)1.1%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
ModificadaAlta (8.8)3.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap24/6/202017/6/2026
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
ModificadaMedia (5.5)0.50%—Sane-project Sane BackendsFedoraproject FedoraDebian LinuxOpensuse Leap+11/6/202017/6/2026
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
ModificadaMedia (6.1)1.2%—Open-xchange Documentconverter-apiOpen-xchange Office WEBOpen-xchange Appsuite BackendOpen-xchange Appsuite Frontend29/3/201717/6/2026
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before…
ModificadaAlta (7.5)3.0%—Opensuse LeapSane-backends Project Sane-backends20/3/201717/6/2026
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
ModificadaMedia (4.3)2.1%—Improved User Search IN Backend Project Improved User Search IN Backend12/8/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in improved-user-search-in-backend.php in the backend in the Improved user search in backend plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that insert XSS sequences via the iusib_meta_fields…
ModificadaAlta (7.5)1.0%—Typo3 Another Backend Login14/11/200816/6/2026
SQL injection vulnerability in TYPO3 Another Backend Login (wrg_anotherbelogin) extension before 0.0.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.8%—SaneSane-backend22/9/200316/6/2026
saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.
ModificadaAlta (7.5)2.1%—SaneSane-backend22/9/200316/6/2026
saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.
ModificadaAlta (7.5)1.9%—SaneSane-backend22/9/200316/6/2026
saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.
ModificadaMedia (5)2.1%—SaneSane-backend22/9/200316/6/2026
saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).
ModificadaMedia (5)1.8%—SaneSane-backend22/9/200316/6/2026
saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).
ModificadaMedia (5)1.8%—SaneSane-backend22/9/200316/6/2026
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).
Orbitaley — Vulnerabilidades