Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 1.9% | — | EventletDnspythonFedoraproject FedoraNetapp Bootstrap OS | 11/4/2024 | 17/6/2026 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name… | |
| Modificada | Media (6.5) | 1.0% | — | Google ChromeFedoraproject Fedora | 10/4/2024 | 17/6/2026 | Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (6.5) | 0.79% | — | Google ChromeFedoraproject Fedora | 10/4/2024 | 17/6/2026 | Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.6) | 0.85% | — | Google ChromeFedoraproject Fedora | 10/4/2024 | 17/6/2026 | Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 95% | — | Apache Traffic ServerDebian LinuxFedoraproject Fedora | 10/4/2024 | 17/6/2026 | HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS… | |
| Modificada | Alta (8.1) | 1.3% | — | Ofono Project OfonoFedoraproject Fedora | 10/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy… | |
| Analizada | Crítica (10) | 20% | 💥 PoC | Fedoraproject FedoraRust-lang Rust | 9/4/2024 | 17/6/2026 | Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. An attacker able to control the arguments passed to the… | |
| Analizada | Alta (7.8) | 85% | — | LibarchiveFedoraproject FedoraMicrosoft Windows 11 22h2Microsoft Windows 11 23h2+1 | 9/4/2024 | 17/6/2026 | Libarchive Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 91% | 💥 PoC | Apache Http ServerFedoraproject FedoraNetapp Ontap | 4/4/2024 | 17/6/2026 | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. | |
| Analizada | Media (6.3) | 2.9% | — | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. | |
| Modificada | Alta (7.3) | 3.9% | 💥 PoC | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | |
| Modificada | Media (4.3) | 0.73% | — | Nodejs UndiciFedoraproject Fedora | 4/4/2024 | 17/6/2026 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1. | |
| Modificada | Crítica (9.8) | 66% | 💥 Exploit | Pgadmin 4Fedoraproject Fedora | 4/4/2024 | 17/6/2026 | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data. | |
| Modificada | Baja (3.5) | 0.80% | — | Nodejs UndiciFedoraproject Fedora | 4/4/2024 | 17/6/2026 | Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1. | |
| Modificada | Media (5.3) | 85% | — | Nghttp2Debian LinuxFedoraproject Fedora | 4/4/2024 | 17/6/2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2… | |
| Analizada | Crítica (9.8) | 1.2% | — | UPXFedoraproject Fedora | 2/4/2024 | 17/6/2026 | A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055.… | |
| Modificada | Alta (8.2) | 0.85% | — | ARM Mbed CryptoARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora | 29/3/2024 | 17/6/2026 | An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory. | |
| Analizada | Alta (8.6) | 36% | — | Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+10 | 27/3/2024 | 17/6/2026 | When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.… | |
| Analizada | Baja (3.5) | 1.7% | — | Haxx CurlFedoraproject FedoraApple MacosNetapp Ontap+6 | 27/3/2024 | 17/6/2026 | When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled.… | |
| Modificada | Alta (7.7) | 18% | 💥 PoC | Google ChromeFedoraproject Fedora | 26/3/2024 | 17/6/2026 | Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.8% | — | Google ChromeFedoraproject Fedora | 26/3/2024 | 17/6/2026 | Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeFedoraproject Fedora | 26/3/2024 | 17/6/2026 | Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 3.4% | — | Google ChromeFedoraproject Fedora | 26/3/2024 | 17/6/2026 | Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Modificada | Alta (7.5) | 1.4% | — | WiresharkFedoraproject Fedora | 26/3/2024 | 17/6/2026 | T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file | |
| Analizada | Media (5.4) | 1.7% | — | Apache Commons ConfigurationFedoraproject Fedora | 21/3/2024 | 17/6/2026 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. |