Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)2.8%💥 PoCRoundcube WebmailDebian LinuxOpensuse Backports SLEOpensuse Leap4/5/202017/6/2026
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
ModificadaAlta (7)0.31%—Opensuse Backports SLEFedoraproject FedoraSqliteodbc Project Sqliteodbc30/4/202017/6/2026
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
ModificadaMedia (6.1)2.3%—GNU MailmanDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+224/4/202017/6/2026
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME…
ModificadaAlta (7.5)3.0%—TeeworldsOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+222/4/202017/6/2026
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
ModificadaAlta (8.8)1.4%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
ModificadaAlta (8.8)1.5%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap13/4/202017/6/2026
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap13/4/202017/6/2026
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+113/4/202017/6/2026
Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.3)1.4%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.3%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+113/4/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
ModificadaAlta (8.8)1.6%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+113/4/202017/6/2026
Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+113/4/202017/6/2026
Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7.5)2.2%—Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap+18/4/202017/6/2026
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
ModificadaAlta (7.5)1.8%—Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap8/4/202017/6/2026
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such…
ModificadaMedia (5.6)0.71%—Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+431/3/202017/6/2026
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections.…
ModificadaAlta (7.5)2.9%—Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap27/3/202017/6/2026
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaAlta (7.5)1.6%—OtrsOpensuse Backports SLEOpensuse LeapDebian Linux27/3/202017/6/2026
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior…
ModificadaMedia (4.3)1.3%—OtrsOpensuse Backports SLEOpensuse LeapDebian Linux27/3/202017/6/2026
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
ModificadaMedia (4.3)1.2%—OtrsOpensuse Backports SLEOpensuse Leap27/3/202017/6/2026
In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
ModificadaAlta (8.8)2.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Orbitaley — Vulnerabilidades