Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.31% | — | MOD Gnutls Project MOD Gnutls | 24/3/2026 | 17/6/2026 | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t x509[]` array without checking the number of certificates is less than or equal to the… | |
| Modificada | Media (6.1) | 0.17% | — | GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux | 23/3/2026 | 1/9/2026 | A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read… | |
| Modificada | Media (5.4) | 0.32% | — | GNU Glibc | 20/3/2026 | 14/7/2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification. | |
| Modificada | Alta (7.5) | 0.33% | — | GNU Glibc | 20/3/2026 | 14/7/2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a… | |
| Modificada | Alta (7.1) | 0.19% | — | GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux | 16/3/2026 | 1/9/2026 | A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure… | |
| Modificada | Alta (7.1) | 0.19% | — | GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux | 16/3/2026 | 1/9/2026 | A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially… | |
| Analizada | Media (4.7) | 0.27% | — | GNU Inetutils | 16/3/2026 | 17/6/2026 | telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR. | |
| Analizada | Crítica (9.8) | 2.4% | — | GNU Inetutils | 13/3/2026 | 17/6/2026 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | |
| Analizada | Media (6.5) | 0.22% | — | GNU Libredwg | 12/3/2026 | 17/6/2026 | Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c. | |
| Modificada | Media (6.2) | 0.16% | — | GNU Glibc | 11/3/2026 | 14/7/2026 | Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses… | |
| Analizada | Media (6.2) | 0.18% | — | GNU Binutils | 9/3/2026 | 17/6/2026 | GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating… | |
| Analizada | Media (6.2) | 0.16% | — | GNU Binutils | 9/3/2026 | 17/6/2026 | GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that… | |
| Analizada | Media (6.2) | 0.18% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines.… | |
| Modificada | Alta (7.5) | 0.52% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an… | |
| Analizada | Alta (7.5) | 0.27% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt… | |
| Modificada | Media (5.5) | 0.24% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later,… | |
| Analizada | Media (5.5) | 0.16% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop… | |
| Analizada | Media (5.5) | 0.17% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was… | |
| Analizada | Media (5) | 0.13% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually… | |
| Modificada | Crítica (9.8) | 0.40% | — | Signumtte Windesk.fm | 27/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection. This issue affects windesk.Fm: before v2.3.4. NOTE: The vendor patched the vulnerability after the CVE was published. | |
| Modificada | Alta (7.8) | 0.20% | — | GNU Inetutils | 27/2/2026 | 17/6/2026 | telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged… | |
| Aplazada | Media (6.3) | 0.76% | — | Liquid PromptAIGNU BashAIZSHAI | 20/2/2026 | 17/6/2026 | Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c on the master branch, arbitrary command injection can lead to code execution when a user enters a directory in a Git repository containing a… | |
| Aplazada | Media (4.8) | 0.25% | — | GNU GlibcAI | 18/2/2026 | 17/6/2026 | An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions. | |
| Aplazada | Media (5.3) | 0.63% | — | GnutlsAI | 9/2/2026 | 1/9/2026 | A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs). | |
| Analizada | Media (5.5) | 0.50% | — | GnupgGpg4win | 27/1/2026 | 17/6/2026 | In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash). |