Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1280 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.2) | 0.16% | — | GNU Binutils | 9/3/2026 | 17/6/2026 | GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that… | |
| Analizada | Media (6.2) | 0.18% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines.… | |
| Modificada | Alta (7.5) | 0.52% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an… | |
| Analizada | Alta (7.5) | 0.27% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt… | |
| Modificada | Media (5.5) | 0.24% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later,… | |
| Analizada | Media (5.5) | 0.16% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop… | |
| Analizada | Media (5.5) | 0.17% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was… | |
| Analizada | Media (5) | 0.13% | — | GNU Binutils | 6/3/2026 | 17/6/2026 | An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually… | |
| Analizada | Crítica (9.8) | 0.67% | 💥 PoC | Faintsnow Hardware Read & Write Utility | 4/3/2026 | 17/6/2026 | An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request. | |
| Modificada | Media (6.5) | 0.47% | — | Redhat Openshift Container PlatformRedhat Enterprise LinuxLinux-nfs Nfs-utils | 4/3/2026 | 1/9/2026 | A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory,… | |
| Analizada | Media (5.2) | 0.14% | — | HP System Event Utility | 3/3/2026 | 17/6/2026 | — | |
| Modificada | Alta (7.8) | 0.20% | 💥 PoC | GNU Inetutils | 27/2/2026 | 17/6/2026 | telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged… | |
| Aplazada | Alta (8.4) | 0.12% | — | IJ Scan UtilityAI | 27/2/2026 | 17/6/2026 | An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service. | |
| Aplazada | Alta (7) | 0.15% | — | Opensuse SdbootutilAI | 25/2/2026 | 17/6/2026 | This issue affects sdbootutil: from ? before 5880246d3a02642dc68f5c8cb474bf63cdb56bca. | |
| Aplazada | Media (5.4) | 0.16% | — | Intel System Firmware Update UtilityAI | 10/2/2026 | 17/6/2026 | Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) Server Boards and Intel(R) Server Systems Based before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined… | |
| Aplazada | Alta (7.1) | 0.12% | — | Intel Server Firmware Update UtilityAI | 10/2/2026 | 17/6/2026 | Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Alta (7.1) | 0.12% | — | Server Firmware Update Utility SysfwupdtAI | 10/2/2026 | 17/6/2026 | Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially… | |
| Aplazada | Media (6.9) | 0.21% | — | Dnsmasq-utilsAI | 5/2/2026 | 17/6/2026 | Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 characters. | |
| Analizada | Alta (8.7) | 0.67% | — | Konicaminolta FTP Utility | 3/2/2026 | 17/6/2026 | Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code. | |
| Analizada | Alta (8.7) | 0.67% | — | Konicaminolta FTP Utility | 3/2/2026 | 17/6/2026 | Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code. | |
| Aplazada | Media (4.6) | 0.48% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine OputilsAI | 30/1/2026 | 17/6/2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details. | |
| Aplazada | Alta (7.1) | 0.45% | — | Johnsoncontrols Istar Configuration UtilityAI | 28/1/2026 | 17/6/2026 | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of the machine hosting the ICU tool. | |
| Aplazada | Alta (8.5) | 0.14% | — | Magic Mouse 2 UtilitiesAI | 25/1/2026 | 17/6/2026 | Magic Mouse 2 Utilities 2.20 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to inject malicious executables and gain elevated system privileges by placing a malicious file in the service path. | |
| Aplazada | Alta (8.5) | 0.15% | — | Realtek Wireless LAN UtilityAI | 21/1/2026 | 17/6/2026 | Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path by inserting malicious code in the system root path that would execute during application startup or… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | GNU InetutilsDebian Linux | 21/1/2026 | 30/9/2026 | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. |