Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
10.010 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 1.4% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+1 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and… | |
| Modificada | Media (5.1) | 0.48% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for… | |
| Modificada | Baja (3.7) | 1.3% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Utility). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and… | |
| Modificada | Baja (3.1) | 0.95% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7… | |
| Modificada | Alta (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 17/7/2023 | 17/6/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modificada | Media (6.7) | 0.26% | — | Google AndroidDebian Linux | 13/7/2023 | 17/6/2026 | In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation. | |
| Modificada | Alta (7.8) | 0.18% | — | Google AndroidDebian Linux | 13/7/2023 | 17/6/2026 | In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Modificada | Media (6.5) | 1.2% | — | LibtiffDebian LinuxRedhat Enterprise Linux | 12/7/2023 | 17/6/2026 | A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service. | |
| Modificada | Media (6.1) | 0.71% | — | Sanitize Project SanitizeDebian Linux | 6/7/2023 | 17/6/2026 | Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that… | |
| Modificada | Media (5) | 0.37% | — | PandocDebian Linux | 5/7/2023 | 17/6/2026 | Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.13 and prior to version 3.1.4, Pandoc is susceptible to an arbitrary file write vulnerability, which can be triggered by providing a specially crafted image element in the… | |
| Modificada | Alta (7.8) | 1.5% | 💥 PoC | Linux KernelDebian LinuxFedoraproject FedoraNetapp H300s+4 | 5/7/2023 | 17/6/2026 | Vulnerabilidad de Lectura/Escritura en nftables Fuera de los Límites del kernel de Linux; nft_byteorder administra incorrectamente los contenidos de registro de VM cuando CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red | |
| Modificada | Alta (7.8) | 1.9% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 5/7/2023 | 17/6/2026 | Vulnerabilidad de Escalada de Privilegios Locales de Use-After-Free de Linux nftables; 'nft_chain_lookup_byid()' no pudo comprobar si una cadena estaba activa y CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red | |
| Modificada | Alta (8.8) | 0.75% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux | 5/7/2023 | 17/6/2026 | Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and… | |
| Modificada | Alta (7.8) | 0.23% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux | 5/7/2023 | 17/6/2026 | When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13. | |
| Modificada | Media (6.5) | 0.74% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux | 5/7/2023 | 17/6/2026 | A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13. | |
| Modificada | Alta (8.8) | 0.76% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux | 5/7/2023 | 17/6/2026 | Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13. | |
| Modificada | Alta (8.8) | 0.76% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux | 5/7/2023 | 17/6/2026 | An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13. | |
| Modificada | Alta (7.5) | 3.0% | — | Djangoproject DjangoDebian LinuxFedoraproject Fedora | 3/7/2023 | 17/6/2026 | In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs. | |
| Modificada | Media (6.5) | 8.3% | 💥 PoC | Linux KernelNetapp Active IQ Unified ManagerDebian Linux | 30/6/2023 | 17/6/2026 | A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system. | |
| Modificada | Alta (7.8) | 0.67% | — | Linux KernelCanonical Ubuntu LinuxDebian Linux | 28/6/2023 | 17/6/2026 | Una vulnerabilidad de use-after-free en el subsistema de io_uring del kernel de Linux puede ser explotada para lograr la escalada de privilegios locales. Ejecutar una solicitud de io_uring cancelar sondeo con un tiempo de espera vinculado puede provocar una UAF en un hrtimer. Recomendamos actualizar al commit anterior… | |
| Modificada | Alta (7.8) | 0.49% | — | Linux KernelDebian Linux | 28/6/2023 | 17/6/2026 | Una vulnerabilidad de escritura fuera de los límites de la memoria en el controlador de red ipvlan del kernel de Linux se puede explotar para lograr la escalada de privilegios locales. La escritura fuera de los límites se debe a la falta de inicialización skb->cb en el controlador de red ipvlan. La vulnerabilidad… | |
| Modificada | Alta (8.8) | 0.66% | — | Google ChromeDebian Linux | 26/6/2023 | 17/6/2026 | Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.2% | — | Google ChromeDebian Linux | 26/6/2023 | 17/6/2026 | Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 56% | — | Google ChromeDebian Linux | 26/6/2023 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.8) | 3.9% | 💥 PoC | Artifex GhostscriptDebian LinuxFedoraproject Fedora | 25/6/2023 | 28/8/2026 | Artifex Ghostscript a través de 10.01.2 maneja mal la validación de permisos para dispositivos pipe (con el prefijo %pipe% o el prefijo | pipe character). |