Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

6914 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.81%—Fedoraproject FedoraWireshark14/5/202417/6/2026
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
ModificadaMedia (5.5)0.42%—WiresharkFedoraproject Fedora14/5/202417/6/2026
Memory handling issue in editcap could cause denial of service via crafted capture file
AnalizadaCrítica (9.6)8.3%⚠ Explotación activaGoogle ChromeFedoraproject Fedora14/5/202417/6/2026
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.1)1.1%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In…
ModificadaAlta (8.8)1.8%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in…
ModificadaAlta (7.2)2.7%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in…
ModificadaAlta (8)13%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from…
ModificadaAlta (8.8)26%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code…
ModificadaMedia (5.4)15%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from…
ModificadaMedia (5.4)0.84%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in…
AnalizadaMedia (4.7)0.90%—CactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others).…
ModificadaMedia (5.5)0.60%—Apple SafariApple IpadosApple Iphone OSApple Macos+514/5/202417/6/2026
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
ModificadaAlta (7.1)0.30%—Linux KernelDebian LinuxFedoraproject Fedora14/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head packet exceeds the user_length, packet_buffer_get will now return 0 to…
ModificadaMedia (5.5)0.24%—Linux KernelFedoraproject Fedora14/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that after the move the old location is simply not available any more. Some…
AnalizadaMedia (5.5)0.30%—Linux KernelDebian LinuxFedoraproject Fedora14/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan->conn will be set to null. But the conn could be…
ModificadaAlta (7.8)0.83%💥 PoCFedoraproject FedoraLinux KernelDebian Linux14/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated…
ModificadaAlta (7.2)86%💥 ExploitCactiFedoraproject Fedora14/5/202417/6/2026
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The…
AnalizadaMedia (6.5)1.2%—Google ChromeFedoraproject Fedora7/5/202417/6/2026
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.6)1.5%—Google ChromeFedoraproject FedoraApple SafariApple Ipados+27/5/202417/6/2026
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (5.2)0.76%—Gnome GlibDebian LinuxFedoraproject FedoraNetapp Ontap Tools7/5/202417/6/2026
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly…
AnalizadaAlta (7.5)3.4%💥 ExploitPalletsprojects WerkzeugDebian LinuxFedoraproject Fedora6/5/202417/6/2026
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger…
ModificadaMedia (5.4)0.98%💥 PoCPalletsprojects JinjaFedoraproject Fedora6/5/202417/6/2026
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to…
AnalizadaAlta (7.5)0.32%—MF GIG Calendar Project MF GIG Calendar6/5/202417/6/2026
The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack
AnalizadaMedia (5.4)0.43%—MF GIG Calendar Project MF GIG Calendar6/5/202417/6/2026
The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (5.4)0.43%—Crelly Slider Project Crelly Slider6/5/202417/6/2026
The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)