Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.29% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. | |
| Modificada | Media (5.3) | 0.54% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | H5P metadata automatically populated the author with the user's username, which could be sensitive information. | |
| Modificada | Media (4.3) | 0.43% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. | |
| Modificada | Alta (8.8) | 1.9% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. | |
| Modificada | Alta (8.8) | 1.9% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/11/2023 | 17/6/2026 | A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. | |
| Modificada | Alta (8.8) | 1.4% | — | Wpvnteam WP Extra | 25/10/2023 | 17/6/2026 | The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the… | |
| Modificada | Crítica (9.8) | 0.64% | — | Mypresta Product Extra Tabs PRO | 17/10/2023 | 17/6/2026 | In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduct()` and `extratabspro::searchmanufacturer().' | |
| Modificada | Media (5.3) | 0.56% | — | Bestwebsoft Profile Extra Fields | 6/10/2023 | 17/6/2026 | The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data,… | |
| Modificada | Media (5.5) | 0.31% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 4/10/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service. | |
| Modificada | Alta (8.8) | 0.31% | — | Futuriowp Futurio Extra | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin. | |
| Modificada | Alta (7.8) | 0.29% | — | Kubernetes Cri-oRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR Power+3 | 25/9/2023 | 17/6/2026 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | |
| Modificada | Media (5.5) | 0.36% | — | Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 14/7/2023 | 17/6/2026 | An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. | |
| Modificada | Media (5.5) | 0.36% | — | Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 14/7/2023 | 17/6/2026 | An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. | |
| Modificada | Media (4.3) | 0.56% | — | Oceanwp Ocean Extra | 12/7/2023 | 17/6/2026 | The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via… | |
| Modificada | Alta (7.8) | 0.39% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure. | |
| Modificada | Alta (7.8) | 0.27% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure. | |
| Modificada | Media (5.5) | 0.28% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. | |
| Modificada | Media (5.5) | 0.21% | — | Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Conditional Cart FEE / Extra Charge Rule FOR Woocommerce Extra Fees | 26/6/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PI Websolution Conditional cart fee plugin <= 1.0.96 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Extra User Details Project Extra User Details | 20/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Vadym K. Extra User Details plugin <= 0.5 versions. | |
| Modificada | Media (5.5) | 0.50% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.37% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Analizada | Alta (7.8) | 3.1% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding. | |
| Modificada | Crítica (9.8) | 8.0% | 💥 PoC | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. |