Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.95% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+1 | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). | |
| Modificada | Alta (7.3) | 1.1% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 2/5/2023 | 17/6/2026 | The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database. | |
| Modificada | Media (5.3) | 6.6% | 💥 Exploit | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 2/5/2023 | 17/6/2026 | The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system. | |
| Modificada | Media (5.5) | 0.59% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 12/4/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.4) | 0.34% | — | Oceanwp Ocean Extra | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.1 versions. Needs the OceanWP theme installed and activated. | |
| Modificada | Media (5.4) | 0.34% | — | Oceanwp Ocean Extra | 30/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions. | |
| Modificada | Media (6.5) | 1.8% | — | HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+5 | 23/3/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability. | |
| Modificada | Media (5.5) | 0.86% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 23/3/2023 | 17/6/2026 | A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When… | |
| Modificada | Media (6.5) | 0.65% | — | Oceanwp Ocean Extra | 13/3/2023 | 17/6/2026 | The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones. | |
| Modificada | Alta (8.8) | 0.76% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 12/12/2022 | 17/6/2026 | The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Crítica (9.8) | 2.1% | — | Rxvt-unicode Project Rxvt-unicodeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/12/2022 | 17/6/2026 | The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set. | |
| Modificada | Media (6.5) | 0.29% | — | QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 29/11/2022 | 17/6/2026 | An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash… | |
| Modificada | Crítica (9.1) | 1.4% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 25/11/2022 | 17/6/2026 | A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP… | |
| Modificada | Alta (7.2) | 1.2% | — | Oceanwp Ocean Extra | 31/10/2022 | 17/6/2026 | The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog. | |
| Modificada | Media (4.3) | 0.66% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | |
| Modificada | Crítica (9.8) | 1.0% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | A limited SQL injection risk was identified in the "browse list of users" site administration page. | |
| Modificada | Alta (7.1) | 0.64% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. | |
| Modificada | Alta (7.5) | 0.81% | — | Apple Swift-nio-extras | 21/9/2022 | 17/6/2026 | Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HTTP request or response bodies. These two objects (HTTPRequestDecompressor and HTTPResponseDecompressor) both failed to detect when the decompressed body was considered complete.… | |
| Modificada | Media (5.5) | 0.49% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 19/9/2022 | 17/6/2026 | A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. | |
| Modificada | Media (5.3) | 0.83% | — | Plextrac | 8/9/2022 | 9/7/2026 | The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their authentication provider take significantly… | |
| Modificada | Alta (7.5) | 1.0% | — | Plextrac | 8/9/2022 | 9/7/2026 | The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid… | |
| Modificada | Alta (8.8) | 0.94% | — | Plextrac | 8/9/2022 | 9/7/2026 | The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections to login as the targeted user. | |
| Modificada | Alta (7.8) | 0.46% | — | LibmodbusFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 29/8/2022 | 17/6/2026 | A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. | |
| Modificada | Baja (3.2) | 0.39% | — | QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Openstack Platform+1 | 17/8/2022 | 17/6/2026 | An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.34% | — | Fedoraproject Extra Packages FOR Enterprise LinuxImagemagickFedoraproject Fedora | 10/8/2022 | 17/6/2026 | In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30. |