Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.40% | — | Zephyr-one Zephyr Project Manager | 15/8/2024 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function.… | |
| Analizada | Media (5.4) | 0.33% | — | Zephyr-one Zephyr Project Manager | 3/8/2024 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Media (4.8) | 0.55% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 2/8/2024 | 17/6/2026 | A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources until it is… | |
| Analizada | Alta (7.5) | 0.45% | — | Zephyr-one Zephyr Project Manager | 1/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99. | |
| Analizada | Media (5.4) | 0.77% | 💥 PoC | Dylanjkotze Zephyr Project Manager | 30/7/2024 | 17/6/2026 | The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Alta (8.8) | 0.44% | — | Zephyr-one Zephyr Project Manager | 9/7/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97. | |
| Analizada | Alta (8.8) | 0.61% | — | Google ChromeFedoraproject Fedora | 24/6/2024 | 17/6/2026 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.61% | — | Google ChromeFedoraproject Fedora | 24/6/2024 | 17/6/2026 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.66% | — | Google ChromeFedoraproject Fedora | 24/6/2024 | 17/6/2026 | Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.61% | — | Google ChromeFedoraproject Fedora | 24/6/2024 | 17/6/2026 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.4) | 0.24% | — | MoodleFedoraproject Fedora | 18/6/2024 | 17/6/2026 | A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two. | |
| Modificada | Alta (8.8) | 0.46% | — | Fedoraproject FedoraMoodle | 18/6/2024 | 17/6/2026 | Incorrect CSRF token checks resulted in multiple CSRF risks. | |
| Analizada | Media (6.1) | 0.37% | — | MoodleFedoraproject Fedora | 18/6/2024 | 17/6/2026 | Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt. | |
| Analizada | Media (5.4) | 0.43% | — | MoodleFedoraproject Fedora | 18/6/2024 | 17/6/2026 | Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. | |
| Modificada | Media (5.3) | 0.35% | — | WP Dummy Content Generator Project WP Dummy Content Generator | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0. | |
| Modificada | Alta (8.8) | 0.47% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.47% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.46% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.54% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.47% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.48% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 5.0% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.41% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.49% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.52% | — | Google ChromeFedoraproject Fedora | 11/6/2024 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |