Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)3.8%💥 PoCLibssh2Fedoraproject FedoraOpensuse LeapDebian Linux+621/10/201917/6/2026
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service…
ModificadaMedia (6.1)1.5%—Bootstrap-3-typeahead Project Bootstrap-3-typeahead8/10/201917/6/2026
Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.
ModificadaMedia (5.4)0.75%—Bootstrapped WP Ultimate Recipe30/8/201917/6/2026
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
ModificadaAlta (7.8)0.57%—Redhat Virt-bootstrap5/7/201917/6/2026
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
ModificadaMedia (5.9)9.7%—Apache ActivemqApache DrillApache ZookeeperDebian Linux+623/5/201917/6/2026
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id…
ModificadaCrítica (9.8)4.9%—Getbootstrap Bootstrap-sass4/4/201917/6/2026
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note…
ModificadaMedia (6.1)16%💥 PoCGetbootstrap BootstrapF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+1220/2/201917/6/2026
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
ModificadaMedia (6.1)4.0%—Getbootstrap Bootstrap9/1/201917/6/2026
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
ModificadaMedia (6.1)3.8%—Getbootstrap Bootstrap9/1/201917/6/2026
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
ModificadaMedia (6.1)4.0%💥 PoCGetbootstrap Bootstrap9/1/201917/6/2026
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
ModificadaMedia (6.1)4.0%💥 PoCGetbootstrap Bootstrap13/7/201817/6/2026
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
ModificadaMedia (6.1)4.3%💥 PoCGetbootstrap Bootstrap13/7/201817/6/2026
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
ModificadaMedia (6.1)4.1%💥 PoCDebian LinuxGetbootstrap Bootstrap13/7/201817/6/2026
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
ModificadaAlta (7.8)0.40%—Amazon WEB Services Cloudformation Bootstrap30/10/201717/6/2026
The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory.
ModificadaAlta (7.5)1.7%—Grml-debootstrap7/8/201717/6/2026
cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users.
ModificadaAlta (7.5)5.5%—Bittorrent Bootstrap-dht13/8/201517/6/2026
The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."
ModificadaAlta (7.5)5.1%—Bittorrent Bootstrap-dht31/10/201417/6/2026
The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which triggers an out-of-bounds read, related to "Improper Indexing."
Orbitaley — Vulnerabilidades