Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▲ 220 respecto a la semana anterior
Críticas / altas1330▼ 101 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

10.010 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.33%—Struktur Libde265Debian Linux1/3/202317/6/2026
Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (6.5)0.77%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaCrítica (9.8)100%💥 ExploitSpipDebian Linux28/2/202317/6/2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
AnalizadaMedia (4.7)0.33%—Debian LinuxLinux KernelNetapp H300s FirmwareNetapp H500s Firmware+325/2/202317/6/2026
In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.
ModificadaMedia (4.2)0.45%—Nodejs Node.jsDebian Linux23/2/202317/6/2026
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
ModificadaMedia (6.5)1.7%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp H300s Firmware+523/2/202317/6/2026
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain"…
ModificadaAlta (8.8)0.98%—Mono-project MonoDebian Linux22/2/202317/6/2026
El paquete mono anterior a 6.8.0.105+dfsg-3.3 para Debian permite la ejecución de código arbitrario porque el tipo MIME application/x-ms-dos-executable está asociado con un intérprete Mono CLR un-sandboxed.
ModificadaMedia (6.5)1.6%—LibreswanDebian Linux21/2/202317/6/2026
Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selector length.
ModificadaCrítica (9.8)1.6%—GNU EmacsDebian Linux20/2/202317/6/2026
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in…
ModificadaAlta (7.5)49%💥 PoCApache Commons FileuploadDebian Linux20/2/20237/10/2026
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
ModificadaAlta (7.4)1.4%—GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+315/2/202317/6/2026
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount…
ModificadaAlta (7.5)63%—Djangoproject DjangoDebian Linux15/2/202317/6/2026
Se descubrió un problema en Multipart Request Parser de Django 3.2 anterior a 3.2.18, 4.0 anterior a 4.0.10 y 4.1 anterior a 4.1.7. Pasar ciertas entradas (por ejemplo, una cantidad excesiva de partes) a formularios de varias partes podría generar demasiados archivos abiertos o agotamiento de la memoria, y…
ModificadaCrítica (9.1)5.4%💥 PoCHaproxyDebian Linux14/2/202317/6/2026
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear…
ModificadaAlta (7.8)0.39%—GpacDebian Linux9/2/202317/6/2026
Desbordamiento de búfer en la región stack de la memoria en el repositorio de GitHub gpac/gpac anterior a 2.2.
ModificadaAlta (7.5)2.3%—Rubyonrails RailsDebian Linux9/2/202317/6/2026
A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the…
ModificadaAlta (7.5)47%💥 PoCDjangoproject DjangoDebian Linux1/2/202317/6/2026
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
AnalizadaAlta (7)3.7%⚠ Explotación activa💥 PoCDebian LinuxLinux Kernel30/1/202317/6/2026
Existe una vulnerabilidad de Use-After-Free en el paquete ALSA PCM en el kernel de Linux. A SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 le faltan bloqueos que se pueden usar en un Use-After-Free que puede resultar en una escalada de privilegios para obtener acceso al anillo 0 por parte del usuario del sistema. Recomendamos…
ModificadaAlta (8.1)0.42%—Lemonldap-ng Apache\Debian Linux27/1/202317/6/2026
En Apache::Session::Browseable anterior a 1.3.6, la validez del certificado X.509 no se verifica de forma predeterminada cuando se conecta a backends LDAP remotos, porque se usa la configuración predeterminada del módulo Net::LDAPS para Perl. NOTA: esto se puede solucionar, por ejemplo, junto con la corrección…
ModificadaAlta (8.1)0.44%—Lemonldap-ng Apache\Debian Linux27/1/202317/6/2026
En Apache::Session::LDAP anterior a 0.5, la validez del certificado X.509 no se verifica de forma predeterminada cuando se conecta a backends LDAP remotos, porque se usa la configuración predeterminada del módulo Net::LDAPS para Perl. NOTA: esto se puede solucionar, por ejemplo, junto con la corrección CVE-2020-16093.