Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

341 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.29%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
ModificadaMedia (5.3)0.54%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
ModificadaMedia (4.3)0.43%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
ModificadaAlta (8.8)1.9%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
ModificadaAlta (8.8)1.9%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
ModificadaAlta (8.8)1.4%—Wpvnteam WP Extra25/10/202317/6/2026
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the…
ModificadaCrítica (9.8)0.64%—Mypresta Product Extra Tabs PRO17/10/202317/6/2026
In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduct()` and `extratabspro::searchmanufacturer().'
ModificadaMedia (5.3)0.56%—Bestwebsoft Profile Extra Fields6/10/202317/6/2026
The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data,…
ModificadaMedia (5.5)0.31%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora4/10/202317/6/2026
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
ModificadaAlta (8.8)0.31%—Futuriowp Futurio Extra3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin.
ModificadaAlta (7.8)0.29%—Kubernetes Cri-oRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR Power+325/9/202317/6/2026
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (4.3)0.56%—Oceanwp Ocean Extra12/7/202317/6/2026
The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via…
ModificadaAlta (7.8)0.39%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
ModificadaAlta (7.8)0.27%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
ModificadaMedia (5.5)0.28%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
ModificadaMedia (5.5)0.21%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
ModificadaMedia (4.8)0.37%—Piwebsolution Conditional Cart FEE / Extra Charge Rule FOR Woocommerce Extra Fees26/6/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PI Websolution Conditional cart fee plugin <= 1.0.96 versions.
ModificadaMedia (4.8)0.40%—Extra User Details Project Extra User Details20/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Vadym K. Extra User Details plugin <= 0.5 versions.
ModificadaMedia (5.5)0.50%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.35%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.37%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
AnalizadaAlta (7.8)3.1%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
ModificadaCrítica (9.8)8.0%💥 PoCImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Orbitaley — Vulnerabilidades