Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.38% | — | SqliteRedhat Enterprise LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service. | |
| Modificada | Alta (8.8) | 0.58% | — | Wpvnteam WP Extra | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2. | |
| Modificada | Media (5.3) | 1.1% | — | EximFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 24/12/2023 | 17/6/2026 | Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other… | |
| Modificada | Media (5.5) | 0.33% | — | Broadcom TcpreplayFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 21/12/2023 | 17/6/2026 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service… | |
| Modificada | Media (5.5) | 0.32% | — | Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 21/12/2023 | 17/6/2026 | An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of… | |
| Modificada | Alta (8.8) | 0.29% | — | Oceanwp Ocean Extra | 19/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2. | |
| Modificada | Alta (8.8) | 0.21% | — | Wpvnteam WP Extra | 19/12/2023 | 17/6/2026 | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects WP EXtra: from n/a through 6.2. | |
| Modificada | Alta (7.8) | 0.31% | — | Ubuntubudgie Budgie Extras | 14/12/2023 | 17/6/2026 | Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from windows, present false information to users,… | |
| Modificada | Alta (7.8) | 0.30% | — | Ubuntubudgie Budgie Extras | 14/12/2023 | 17/6/2026 | Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users… | |
| Modificada | Alta (7.8) | 0.30% | — | Ubuntubudgie Budgie Extras | 14/12/2023 | 17/6/2026 | Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or… | |
| Modificada | Alta (7.8) | 0.30% | — | Ubuntubudgie Budgie Extras | 14/12/2023 | 17/6/2026 | Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to… | |
| Modificada | Alta (7.8) | 0.30% | — | Ubuntubudgie Budgie Extras | 14/12/2023 | 17/6/2026 | Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or… | |
| Modificada | Alta (7.8) | 0.31% | — | Ubuntubudgie Budgie Extras | 14/12/2023 | 17/6/2026 | Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or… | |
| Modificada | Media (5.4) | 0.38% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.2. | |
| Modificada | Alta (7.8) | 0.54% | — | Redhat AnsibleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Ansible Automation Platform+2 | 12/12/2023 | 17/6/2026 | A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data. | |
| Modificada | Media (5.4) | 0.42% | — | Venutius BP Profile Shortcodes Extra | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra plugin <= 2.5.2 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Wpvnteam WP Extra | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra plugin <= 6.4 versions. | |
| Modificada | Media (4.3) | 0.39% | — | Wpvnteam WP Extra | 22/11/2023 | 17/6/2026 | The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a… | |
| Modificada | Media (5.5) | 0.48% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 19/11/2023 | 17/6/2026 | A heap use-after-free flaw was found in coders/bmp.c in ImageMagick. | |
| Modificada | Media (4.8) | 0.42% | — | Actpro Extra Product Options FOR Woocommerce | 14/11/2023 | 17/6/2026 | Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in actpro Extra Product Options for WooCommerce plugin <= 3.0.3 versions. | |
| Modificada | Media (6.1) | 0.22% | — | Vadimk Extra User Details | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vadym K. Extra User Details allows Stored XSS.This issue affects Extra User Details: from n/a through 0.5. | |
| Modificada | Baja (3.3) | 0.24% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting. | |
| Modificada | Baja (3.3) | 0.28% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. | |
| Modificada | Crítica (9.8) | 1.4% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution. | |
| Modificada | Media (5.3) | 0.56% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. |