Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.33%—FfmpegFedoraproject Fedora17/4/202417/6/2026
FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.8)0.34%—FfmpegFedoraproject Fedora17/4/202417/6/2026
FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.
ModificadaCrítica (9.8)1.1%—FfmpegFedoraproject Fedora17/4/202417/6/2026
FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.
ModificadaAlta (7.5)0.87%—LibcoapFedoraproject Fedora17/4/202417/6/2026
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
AnalizadaMedia (6.5)0.98%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.5)1.2%—FfmpegFedoraproject Fedora17/4/202417/6/2026
FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.
AnalizadaMedia (6.1)0.89%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
AnalizadaMedia (4.3)0.92%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
AnalizadaMedia (4.3)0.85%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)
AnalizadaMedia (4.3)0.72%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
AnalizadaMedia (4.3)0.65%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaMedia (6.1)0.73%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)
AnalizadaAlta (7.5)0.85%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaAlta (8.8)18%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject Fedora17/4/202417/6/2026
Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (4.9)0.42%—Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+316/4/202417/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL…
AnalizadaAlta (8.8)1.1%—Net-snmpDebian LinuxFedoraproject Fedora16/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and…
AnalizadaMedia (6.5)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3…
AnalizadaMedia (6.5)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong…
AnalizadaMedia (6.5)1.0%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch.…
AnalizadaMedia (5.3)1.1%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use…
AnalizadaAlta (8.8)1.3%—Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+1116/4/202417/6/2026
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users…
ModificadaMedia (5.9)5.8%💥 PoCPuttyFilezilla-project Filezilla ClientWinscpTortoisegit+215/4/202417/6/2026
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of…
AnalizadaAlta (7.5)0.96%—PydanticFedoraproject Fedora15/4/202417/6/2026
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
ModificadaAlta (8)0.40%—FfmpegFedoraproject Fedora12/4/202417/6/2026
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.