Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.44% | — | GnupgGpg4win | 27/1/2026 | 15/7/2026 | In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys. | |
| Modificada | Crítica (9.8) | 1.8% | — | GnupgGpg4win | 27/1/2026 | 15/7/2026 | In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote… | |
| Aplazada | Media (4) | 0.23% | — | GnutlsAI | 26/1/2026 | 1/9/2026 | A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | GNU InetutilsDebian Linux | 21/1/2026 | 30/9/2026 | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | |
| Analizada | Alta (7.5) | 0.50% | — | GNU Glibc | 20/1/2026 | 17/6/2026 | Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. | |
| Analizada | Alta (7.5) | 0.63% | 💥 PoC | GNU Glibc | 15/1/2026 | 17/6/2026 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver. | |
| Analizada | Alta (8.4) | 0.39% | — | GNU Glibc | 14/1/2026 | 17/6/2026 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the… | |
| Analizada | Alta (8.8) | 0.35% | — | GNU Wget2 | 9/1/2026 | 17/6/2026 | A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted URL, which, upon user… | |
| Analizada | Crítica (9.8) | 0.79% | 💥 PoC | GNU Wget2 | 9/1/2026 | 17/6/2026 | A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow… | |
| Analizada | Alta (7.5) | 1.2% | — | GNU Libtasn1 | 7/1/2026 | 17/6/2026 | Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string. | |
| Analizada | Alta (7.5) | 0.36% | — | GNU Recutils | 30/12/2025 | 17/6/2026 | A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password. | |
| Analizada | Alta (7.5) | 0.31% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.38% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.24% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.38% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.37% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Baja (2.5) | 0.15% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file. | |
| Modificada | Alta (7) | 0.15% | — | Gnupg | 28/12/2025 | 17/6/2026 | In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.) | |
| Analizada | Media (4.7) | 0.11% | — | Gnupg | 27/12/2025 | 17/6/2026 | In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification).… | |
| Aplazada | Alta (8.5) | 0.39% | — | GNU BarcodeAI | 24/12/2025 | 17/6/2026 | GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system. | |
| Aplazada | Media (4.9) | 0.14% | — | GNU Grub2AI | 18/11/2025 | 1/9/2026 | A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been… | |
| Aplazada | Media (4.9) | 0.13% | — | GNU Grub2AI | 18/11/2025 | 1/9/2026 | A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the module is unloaded. An attacker who can execute this command can force the… | |
| Modificada | Alta (7.8) | 0.20% | — | GNU Grub2 | 18/11/2025 | 1/9/2026 | A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory… | |
| Aplazada | Media (4.8) | 0.19% | — | GNU GrubAI | 18/11/2025 | 1/9/2026 | A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB… | |
| Aplazada | Media (4.9) | 0.14% | — | GNU GrubAI | 18/11/2025 | 1/9/2026 | A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to… |