Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 3.8% | 💥 PoC | Libssh2Fedoraproject FedoraOpensuse LeapDebian Linux+6 | 21/10/2019 | 17/6/2026 | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service… | |
| Modificada | Media (6.1) | 1.5% | — | Bootstrap-3-typeahead Project Bootstrap-3-typeahead | 8/10/2019 | 17/6/2026 | Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser. | |
| Modificada | Media (5.4) | 0.75% | — | Bootstrapped WP Ultimate Recipe | 30/8/2019 | 17/6/2026 | The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. | |
| Modificada | Alta (7.8) | 0.57% | — | Redhat Virt-bootstrap | 5/7/2019 | 17/6/2026 | virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py. | |
| Modificada | Media (5.9) | 9.7% | — | Apache ActivemqApache DrillApache ZookeeperDebian Linux+6 | 23/5/2019 | 17/6/2026 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id… | |
| Modificada | Crítica (9.8) | 4.9% | — | Getbootstrap Bootstrap-sass | 4/4/2019 | 17/6/2026 | Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note… | |
| Modificada | Media (6.1) | 16% | 💥 PoC | Getbootstrap BootstrapF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+12 | 20/2/2019 | 17/6/2026 | In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. | |
| Modificada | Media (6.1) | 4.0% | — | Getbootstrap Bootstrap | 9/1/2019 | 17/6/2026 | In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. | |
| Modificada | Media (6.1) | 3.8% | — | Getbootstrap Bootstrap | 9/1/2019 | 17/6/2026 | In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Getbootstrap Bootstrap | 9/1/2019 | 17/6/2026 | In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041. | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Getbootstrap Bootstrap | 13/7/2018 | 17/6/2026 | In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. | |
| Modificada | Media (6.1) | 4.3% | 💥 PoC | Getbootstrap Bootstrap | 13/7/2018 | 17/6/2026 | In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. | |
| Modificada | Media (6.1) | 4.1% | 💥 PoC | Debian LinuxGetbootstrap Bootstrap | 13/7/2018 | 17/6/2026 | In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. | |
| Modificada | Alta (7.8) | 0.40% | — | Amazon WEB Services Cloudformation Bootstrap | 30/10/2017 | 17/6/2026 | The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory. | |
| Modificada | Alta (7.5) | 1.7% | — | Grml-debootstrap | 7/8/2017 | 17/6/2026 | cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users. | |
| Modificada | Alta (7.5) | 5.5% | — | Bittorrent Bootstrap-dht | 13/8/2015 | 17/6/2026 | The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing." | |
| Modificada | Alta (7.5) | 5.1% | — | Bittorrent Bootstrap-dht | 31/10/2014 | 17/6/2026 | The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which triggers an out-of-bounds read, related to "Improper Indexing." |