Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.74%—Gnome-remote-desktopCanonical Ubuntu Linux31/1/202517/6/2026
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
AplazadaAlta (8.8)0.82%—Ggnome Garden Gnome PackageAI8/1/202517/6/2026
The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that automatically extracts 'ggpkg' files that have been uploaded in all versions up to, and including, 2.3.0. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.8)0.98%—Gnome-maps17/11/202417/6/2026
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.
AnalizadaCrítica (9.8)1.3%—Gnome GlibDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Tools11/11/202417/6/2026
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
ModificadaAlta (7.5)0.93%—Gnome Libsoup11/11/202417/6/2026
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.
ModificadaMedia (6.5)0.68%—Gnome Libsoup11/11/202417/6/2026
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).
ModificadaAlta (7.5)0.78%—Gnome Libsoup11/11/202417/6/2026
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.
ModificadaAlta (7.8)0.46%—Gnome Libgsf3/10/202417/6/2026
An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can…
ModificadaAlta (7.8)0.40%—Gnome Libgsf3/10/202417/6/2026
An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used…
AnalizadaMedia (5.4)0.41%—Ggnome Garden Gnome Package24/9/202417/6/2026
The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.5)0.57%—Gnome Remote DesktopAI2/9/202417/6/2026
A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to…
AplazadaMedia (4.3)0.32%—Gnome Settings DaemonAILinux KernelAI16/6/202417/6/2026
Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem…
AplazadaMedia (4.4)0.24%—Gnome VTEAI9/6/202417/6/2026
GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.
AplazadaMedia (6.5)0.34%—Gnome ShellAI28/5/202417/6/2026
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts…
ModificadaMedia (5.2)0.76%—Gnome GlibDebian LinuxFedoraproject FedoraNetapp Ontap Tools7/5/202417/6/2026
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly…
AnalizadaMedia (5.5)0.21%—Gnome Glade19/2/202417/6/2026
plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).
ModificadaAlta (7.8)0.41%—Gnome Gdkpixbuf26/1/202417/6/2026
In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code…
ModificadaMedia (5.4)0.55%—Ggnome Garden Gnome Package22/11/202317/6/2026
The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shortcode in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaAlta (7.7)0.86%—Gnome Tracker MinersRedhat Enterprise Linux13/10/202317/6/2026
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
ModificadaMedia (5.5)0.30%—Gnome-shellFedoraproject Fedora22/9/202317/6/2026
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
ModificadaMedia (5.5)0.39%—Gnome Glib14/9/202317/6/2026
A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.
ModificadaAlta (7.8)0.36%—Gnome Glib14/9/202317/6/2026
A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for…
ModificadaAlta (7.5)0.77%—Gnome Glib14/9/202317/6/2026
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who…
ModificadaMedia (5.5)0.38%—Gnome Glib14/9/202323/6/2026
A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.
ModificadaAlta (7.5)0.76%—Gnome Glib14/9/202317/6/2026
A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.
Orbitaley — Vulnerabilidades