Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.61% | — | GNU Binutils | 10/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be… | |
| Analizada | Baja (2.3) | 0.61% | — | GNU Binutils | 10/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation… | |
| Analizada | Baja (2.3) | 0.58% | — | GNU Binutils | 10/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The… | |
| Modificada | Baja (2.3) | 0.64% | — | GNU Binutils | 10/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is… | |
| Modificada | Baja (2.3) | 0.67% | — | GNU Binutils | 10/2/2025 | 17/6/2026 | A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The… | |
| Aplazada | Crítica (9.1) | 0.49% | — | Utils-extendAI | 5/2/2025 | 17/6/2026 | The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence. | |
| Aplazada | Alta (7.5) | 0.40% | — | Xe-utilsAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Analizada | Media (6.3) | 0.75% | — | GNU Binutils | 29/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack… | |
| Aplazada | Media (5.5) | 0.25% | — | GNU BinutilsAI | 21/1/2025 | 17/6/2026 | https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function. | |
| Aplazada | Baja (3.6) | 0.43% | 💥 PoC | Shadow-utils ShadowAI | 26/12/2024 | 17/6/2026 | shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap… | |
| Aplazada | Media (6.3) | 0.76% | — | XZ UtilsAI | 2/10/2024 | 17/6/2026 | XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerability. If a command line contains Unicode characters (for example, filenames) that… | |
| Modificada | Alta (7.8) | 1.1% | — | Nagios Ndoutils | 7/8/2024 | 17/6/2026 | Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user. | |
| Aplazada | Alta (8.1) | 0.56% | — | Che3vinci C3/utilsAI | 1/7/2024 | 17/6/2026 | che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Aplazada | Crítica (9.8) | 0.69% | — | Ahilfoley Cahil UtilsAI | 1/7/2024 | 17/6/2026 | ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Modificada | Alta (8.8) | 1.1% | — | Csutils Csmock | 10/4/2024 | 17/6/2026 | A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers. | |
| Aplazada | Alta (7.5) | 0.71% | — | Web3-utilsAI | 25/3/2024 | 17/6/2026 | Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected… | |
| Analizada | Media (4) | 0.31% | — | Elfutils Project Elfutils | 20/2/2024 | 17/6/2026 | elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. | |
| Modificada | Media (5.5) | 0.49% | 💥 PoC | GNU Coreutils | 6/2/2024 | 17/6/2026 | A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service. | |
| Modificada | Alta (8.6) | 47% | 💥 Exploit | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+3 | 8/1/2024 | 17/6/2026 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | |
| Modificada | Media (5.5) | 0.26% | — | Shadow-maint Shadow-utilsRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR IBM Z Systems+5 | 27/12/2023 | 17/6/2026 | A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (4.3) | 0.69% | — | Codehaus-plexus Plexus-utilsRedhat Integration Camel K | 25/9/2023 | 17/6/2026 | A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection. | |
| Analizada | Alta (7.5) | 1.3% | 💥 PoC | Codehaus-plexus Plexus-utilsRedhat Integration Camel K | 25/9/2023 | 17/6/2026 | A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access… | |
| Modificada | Media (5.5) | 0.38% | — | GNU Binutils | 14/9/2023 | 17/6/2026 | A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | GNU Binutils | 14/9/2023 | 17/6/2026 | A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service. |