Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
10.167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Alta (8.8) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.88% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.88% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.95% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.76% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.6% | — | FrroutingFedoraproject FedoraDebian Linux | 3/4/2023 | 17/6/2026 | Se encontró una afirmación accesible en Frrouting frr-bgpd 8.3.0 en la función peek_for_as4_capability. Los atacantes pueden construir maliciosamente paquetes abiertos BGP y enviarlos a pares BGP que ejecutan frr-bgpd, lo que resulta en DoS. | |
| Modificada | Crítica (9.8) | 6.3% | — | Artifex GhostscriptDebian Linux | 31/3/2023 | 17/6/2026 | En Artifex Ghostscript hasta la versión 10.01.0, hay un desbordamiento de búfer que puede corromper los datos internos del intérprete PostScript, en base/sbcp.c. Esto afecta a BCPEncode, BCPDecode, TBCPEncode y TBCPDecode. Si el búfer de escritura se llena hasta un byte menos de su capacidad, y se intenta escribir un… | |
| Modificada | Media (5.3) | 2.5% | — | Ruby-lang RubyRuby-lang TimeDebian LinuxFedoraproject Fedora | 31/3/2023 | 17/6/2026 | A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2. | |
| Modificada | Media (5.3) | 2.6% | — | Ruby-lang URIDebian LinuxFedoraproject Fedora | 31/3/2023 | 17/6/2026 | A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1. | |
| Modificada | Media (5.5) | 1.2% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the… | |
| Modificada | Media (5.9) | 1.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+6 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI… | |
| Modificada | Media (5.9) | 1.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+6 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as… | |
| Modificada | Crítica (9.8) | 4.4% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of… | |
| Modificada | Crítica (9.8) | 2.8% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which… | |
| Modificada | Crítica (9.8) | 3.8% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper validation of user-supplied data, which… | |
| Modificada | Crítica (9.8) | 4.4% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper validation of the length of user-supplied data… | |
| Modificada | Crítica (9.8) | 8.6% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble… | |
| Modificada | Crítica (9.8) | 4.4% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data… |