Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1280 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.21% | — | Oracle Utilities Framework | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General). Supported versions that are affected are 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4 and 25.10. Easily exploitable vulnerability allows low privileged attacker with network access… | |
| Analizada | Alta (7.5) | 0.36% | — | GNU Recutils | 30/12/2025 | 17/6/2026 | A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password. | |
| Aplazada | Media (6.3) | 0.14% | — | AsteriskAIMicro Registration UtilityAI | 29/12/2025 | 7/10/2026 | Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts a special federation name and characters treated special by asterisk can be injected into the `Dial( )` application due… | |
| Analizada | Alta (7.5) | 0.31% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.38% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.24% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.38% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Baja (2.5) | 0.15% | — | GNU Binutils | 29/12/2025 | 17/6/2026 | An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file. | |
| Analizada | Alta (7.5) | 0.37% | — | GNU Binutils | 29/12/2025 | 7/10/2026 | A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file. | |
| Analizada | Media (4.8) | 0.40% | — | HP Omen Gaming HUBHP System Event Utility | 9/12/2025 | 17/6/2026 | HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential vulnerability was remediated with HP System Event Utility version 3.2.12 and Omen Gaming Hub version 1101.2511.101.0. | |
| Analizada | Crítica (9.3) | 0.47% | — | Gofiber Utils | 9/12/2025 | 17/6/2026 | Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, both functions silently fall back to returning predictable UUID values, including the zero UUID "00000000-0000-0000-0000-000000000000". The… | |
| Aplazada | Media (6.1) | 0.19% | — | Util-linuxAI | 5/12/2025 | 1/9/2026 | A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database. | |
| Analizada | Media (6.9) | 0.30% | — | Unifiedjs Mdast-util-to-hast | 1/12/2025 | 17/6/2026 | mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in… | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Server Configuration UtilityAIIntel Server Firmware Update UtilityAI | 11/11/2025 | 17/6/2026 | Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user… | |
| Aplazada | Media (5.4) | 0.14% | — | Intel System Support UtilityAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur… | |
| Aplazada | Alta (8.5) | 0.24% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This… | |
| Modificada | Baja (1.9) | 0.28% | — | GNU Binutils | 16/10/2025 | 17/6/2026 | A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called… | |
| Modificada | Baja (1.9) | 0.28% | — | GNU Binutils | 16/10/2025 | 17/6/2026 | A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. | |
| Modificada | Baja (1.9) | 0.24% | — | GNU Binutils | 8/10/2025 | 30/9/2026 | A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be… | |
| Modificada | Baja (1.9) | 0.21% | — | GNU Binutils | 8/10/2025 | 30/9/2026 | A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is… | |
| Modificada | Baja (1.9) | 0.21% | — | GNU Binutils | 7/10/2025 | 17/6/2026 | A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized.… | |
| Modificada | Baja (1.9) | 0.22% | — | GNU Binutils | 7/10/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version… | |
| Modificada | Baja (1.9) | 0.21% | — | GNU Binutils | 7/10/2025 | 17/6/2026 | A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The… |