Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

10.010 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.7)1.4%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+118/7/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and…
ModificadaMedia (5.1)0.48%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+618/7/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for…
ModificadaBaja (3.7)1.3%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+618/7/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Utility). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and…
ModificadaBaja (3.1)0.95%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+618/7/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7…
ModificadaAlta (7.5)2.0%—ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+217/7/202317/6/2026
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
ModificadaMedia (6.7)0.26%—Google AndroidDebian Linux13/7/202317/6/2026
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
ModificadaAlta (7.8)0.18%—Google AndroidDebian Linux13/7/202317/6/2026
In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
ModificadaMedia (6.5)1.2%—LibtiffDebian LinuxRedhat Enterprise Linux12/7/202317/6/2026
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
ModificadaMedia (6.1)0.71%—Sanitize Project SanitizeDebian Linux6/7/202317/6/2026
Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that…
ModificadaMedia (5)0.37%—PandocDebian Linux5/7/202317/6/2026
Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.13 and prior to version 3.1.4, Pandoc is susceptible to an arbitrary file write vulnerability, which can be triggered by providing a specially crafted image element in the…
ModificadaAlta (7.8)1.5%💥 PoCLinux KernelDebian LinuxFedoraproject FedoraNetapp H300s+45/7/202317/6/2026
Vulnerabilidad de Lectura/Escritura en nftables Fuera de los Límites del kernel de Linux; nft_byteorder administra incorrectamente los contenidos de registro de VM cuando CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red
ModificadaAlta (7.8)1.9%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux5/7/202317/6/2026
Vulnerabilidad de Escalada de Privilegios Locales de Use-After-Free de Linux nftables; 'nft_chain_lookup_byid()' no pudo comprobar si una cadena estaba activa y CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red
ModificadaAlta (8.8)0.75%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and…
ModificadaAlta (7.8)0.23%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaMedia (6.5)0.74%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaAlta (8.8)0.76%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaAlta (8.8)0.76%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaAlta (7.5)3.0%—Djangoproject DjangoDebian LinuxFedoraproject Fedora3/7/202317/6/2026
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
ModificadaMedia (6.5)8.3%💥 PoCLinux KernelNetapp Active IQ Unified ManagerDebian Linux30/6/202317/6/2026
A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.
ModificadaAlta (7.8)0.67%—Linux KernelCanonical Ubuntu LinuxDebian Linux28/6/202317/6/2026
Una vulnerabilidad de use-after-free en el subsistema de io_uring del kernel de Linux puede ser explotada para lograr la escalada de privilegios locales. Ejecutar una solicitud de io_uring cancelar sondeo con un tiempo de espera vinculado puede provocar una UAF en un hrtimer. Recomendamos actualizar al commit anterior…
ModificadaAlta (7.8)0.49%—Linux KernelDebian Linux28/6/202317/6/2026
Una vulnerabilidad de escritura fuera de los límites de la memoria en el controlador de red ipvlan del kernel de Linux se puede explotar para lograr la escalada de privilegios locales. La escritura fuera de los límites se debe a la falta de inicialización skb-&gt;cb en el controlador de red ipvlan. La vulnerabilidad…
ModificadaAlta (8.8)0.66%—Google ChromeDebian Linux26/6/202317/6/2026
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.2%—Google ChromeDebian Linux26/6/202317/6/2026
Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)56%—Google ChromeDebian Linux26/6/202317/6/2026
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.8)3.9%💥 PoCArtifex GhostscriptDebian LinuxFedoraproject Fedora25/6/202328/8/2026
Artifex Ghostscript a través de 10.01.2 maneja mal la validación de permisos para dispositivos pipe (con el prefijo %pipe% o el prefijo | pipe character).