Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.83%💥 PoCFedoraproject FedoraLinux KernelDebian Linux14/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated…
ModificadaAlta (7.2)86%💥 ExploitCactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The…
AnalizadaMedia (6.5)1.2%—Google ChromeFedoraproject Fedora7/5/202417/6/2026
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.6)1.5%—Google ChromeFedoraproject FedoraApple SafariApple Ipados+27/5/202417/6/2026
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (5.2)0.76%—Gnome GlibDebian LinuxFedoraproject FedoraNetapp Ontap Tools7/5/202417/6/2026
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly…
AnalizadaAlta (7.5)3.4%💥 ExploitPalletsprojects WerkzeugDebian LinuxFedoraproject Fedora6/5/202417/6/2026
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger…
ModificadaMedia (5.4)0.98%💥 PoCPalletsprojects JinjaFedoraproject Fedora6/5/202417/6/2026
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to…
ModificadaAlta (7.4)0.67%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.
ModificadaAlta (7.5)0.90%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time,…
ModificadaCrítica (9.8)0.41%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.
ModificadaMedia (6.1)0.47%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.
ModificadaMedia (5.9)1.3%—Uriparser Project UriparserFedoraproject Fedora3/5/202417/6/2026
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
ModificadaAlta (8.6)1.2%—Uriparser Project UriparserFedoraproject Fedora3/5/202417/6/2026
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
AnalizadaAlta (7.5)1.1%—Rjbs Email-mimeFedoraproject Fedora2/5/202417/6/2026
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
AnalizadaMedia (5.4)0.46%—Pgadmin 4Fedoraproject Fedora2/5/202417/6/2026
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
AnalizadaAlta (8.8)0.63%—Pgadmin 4Fedoraproject Fedora2/5/202417/6/2026
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL…
ModificadaCrítica (9.8)1.4%—Nothings STB Vorbis.cFedoraproject Fedora1/5/202417/6/2026
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (8.8)1.1%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)1.2%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.5)1.0%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.5)0.90%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)9.0%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
ModificadaAlta (7.8)0.18%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: Binding devm_led_classdev_register() to the netdev is problematic because on module removal we get a RTNL-related deadlock. Fix this by avoiding the device-managed LED functions. Note: We can safely call led_classdev_unregister() for a LED even if…
ModificadaMedia (4.7)0.21%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() nft_unregister_obj() can concurrent with __nft_obj_type_get(), and there is not any protection when iterate over nf_tables_objects list in __nft_obj_type_get(). Therefore, there is…
ModificadaAlta (7.8)0.64%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip conntrack input hook for promisc packets For historical reasons, when bridge device is in promisc mode, packets that are directed to the taps follow bridge input hook path. This patch adds a workaround to reset conntrack…