Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

341 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.38%—SqliteRedhat Enterprise LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/1/202417/6/2026
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
ModificadaAlta (8.8)0.58%—Wpvnteam WP Extra29/12/202317/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2.
ModificadaMedia (5.3)1.1%—EximFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux24/12/202317/6/2026
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other…
ModificadaMedia (5.5)0.33%—Broadcom TcpreplayFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora21/12/202317/6/2026
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service…
ModificadaMedia (5.5)0.32%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora21/12/202317/6/2026
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of…
ModificadaAlta (8.8)0.29%—Oceanwp Ocean Extra19/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.
ModificadaAlta (8.8)0.21%—Wpvnteam WP Extra19/12/202317/6/2026
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects WP EXtra: from n/a through 6.2.
ModificadaAlta (7.8)0.31%—Ubuntubudgie Budgie Extras14/12/202317/6/2026
Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from windows, present false information to users,…
ModificadaAlta (7.8)0.30%—Ubuntubudgie Budgie Extras14/12/202317/6/2026
Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users…
ModificadaAlta (7.8)0.30%—Ubuntubudgie Budgie Extras14/12/202317/6/2026
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or…
ModificadaAlta (7.8)0.30%—Ubuntubudgie Budgie Extras14/12/202317/6/2026
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to…
ModificadaAlta (7.8)0.30%—Ubuntubudgie Budgie Extras14/12/202317/6/2026
Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or…
ModificadaAlta (7.8)0.31%—Ubuntubudgie Budgie Extras14/12/202317/6/2026
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or…
ModificadaMedia (5.4)0.38%—Averta Shortcodes AND Extra Features FOR Phlox Theme14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.2.
ModificadaAlta (7.8)0.54%—Redhat AnsibleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Ansible Automation Platform+212/12/202317/6/2026
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
ModificadaMedia (5.4)0.42%—Venutius BP Profile Shortcodes Extra22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra plugin <= 2.5.2 versions.
ModificadaAlta (8.8)0.26%—Wpvnteam WP Extra22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra plugin <= 6.4 versions.
ModificadaMedia (4.3)0.39%—Wpvnteam WP Extra22/11/202317/6/2026
The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a…
ModificadaMedia (5.5)0.48%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora19/11/202317/6/2026
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
ModificadaMedia (4.8)0.42%—Actpro Extra Product Options FOR Woocommerce14/11/202317/6/2026
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in actpro Extra Product Options for WooCommerce plugin <= 3.0.3 versions.
ModificadaMedia (6.1)0.22%—Vadimk Extra User Details13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Vadym K. Extra User Details allows Stored XSS.This issue affects Extra User Details: from n/a through 0.5.
ModificadaBaja (3.3)0.24%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
ModificadaBaja (3.3)0.28%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
ModificadaCrítica (9.8)1.4%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
ModificadaMedia (5.3)0.56%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
Orbitaley — Vulnerabilidades