Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
10.167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Apache Traffic ServerDebian Linux | 14/6/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0. | |
| Modificada | Alta (8.8) | 13% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 14% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Baja (3.9) | 14% | ⚠ Explotación activa | Vmware ToolsDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux | 9/6/2023 | 17/6/2026 | A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | |
| Modificada | Media (6.5) | 1.4% | — | Freedesktop DbusFedoraproject FedoraDebian Linux | 8/6/2023 | 17/6/2026 | D-Bus en versiones anteriores a v1.15.6 a veces permite a usuarios sin privilegios bloquear el "dbus-daemon". Si un usuario privilegiado con control sobre "dbus-daemon" está usando la interfaz "org.freedesktop.DBus.Monitoring" para monitorizar el tráfico del bus de mensajes, entonces un usuario sin privilegios con la… | |
| Modificada | Media (6.5) | 2.3% | — | WiresharkDebian Linux | 7/6/2023 | 17/6/2026 | Debido a un fallo en la validación de la longitud proporcionada por un atacante de paquetes IEEE-C37.118, Wireshark v4.0.5 y anteriores, por defecto, es susceptible a un desbordamiento de búfer de la pila, y posiblemente la ejecución de código en el contexto del proceso que ejecuta Wireshark. | |
| Modificada | Media (6.5) | 2.3% | — | WiresharkDebian Linux | 7/6/2023 | 17/6/2026 | Debido a un fallo en la validación de la longitud proporcionada por un atacante de paquetes manipulados RTPS, Wireshark v4.0.5 y anteriores, por defecto, es susceptible a un desbordamiento de búfer de pila y posiblemente la ejecución de código en el contexto del proceso que ejecuta Wireshark. | |
| Modificada | Alta (7.8) | 0.58% | 💥 PoC | Libcap Project LibcapRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 6/6/2023 | 17/6/2026 | A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB. | |
| Modificada | Baja (3.3) | 0.35% | — | Libcap Project LibcapRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora | 6/6/2023 | 17/6/2026 | A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory. | |
| Modificada | Media (6.5) | 1.1% | — | Yajl Project YajlFedoraproject FedoraDebian Linux | 6/6/2023 | 17/6/2026 | There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash. | |
| Modificada | Alta (7.8) | 0.44% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+3 | 5/6/2023 | 17/6/2026 | A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). | |
| Analizada | Alta (8.8) | 38% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraDebian LinuxCouchbase Server | 5/6/2023 | 8/10/2026 | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.3) | 0.74% | — | Debian LinuxFedoraproject FedoraQT | 5/6/2023 | 17/6/2026 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. | |
| Modificada | Media (5.5) | 1.5% | — | Openprinting CupsDebian Linux | 1/6/2023 | 17/6/2026 | OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function `format_log_line` could allow remote attackers to cause a DoS on the affected… | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelSuse Linux EnterpriseDebian Linux | 31/5/2023 | 17/6/2026 | Se ha descubierto un problema en el kernel de Linux en las versiones anteriores a 6.3.3. Hay una lectura fuera de límites en crc16 en "lib/crc16.c" cuando se llama dese "fs/ext4/super.c" porque "ext4_group_desc_csum" no comprueba correctamente un desplazamiento. | |
| Modificada | Media (6.5) | 1.1% | — | WiresharkDebian Linux | 30/5/2023 | 17/6/2026 | El bucle infinito del disector XRA en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio mediante la inyección de paquetes o un archivo de captura manipulado | |
| Analizada | Media (5.5) | 0.95% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+1 | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). | |
| Modificada | Media (6.5) | 75% | — | OpensslDebian Linux | 30/5/2023 | 17/6/2026 | Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long… | |
| Analizada | Media (5.3) | 0.88% | — | Debian LinuxQT | 28/5/2023 | 17/6/2026 | An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this… | |
| Modificada | Alta (7.5) | 1.1% | — | Signalwire Sofia-sipDebian Linux | 26/5/2023 | 17/6/2026 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in stun_parse_attr_error_code and… | |
| Modificada | Media (4.7) | 0.19% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+3 | 26/5/2023 | 17/6/2026 | There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. | |
| Modificada | Alta (7.5) | 1.6% | — | WiresharkDebian Linux | 26/5/2023 | 17/6/2026 | GDSDB bucle infinito en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de inyección de paquetes o archivo de captura manipulado |