Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)1.9%—EventletDnspythonFedoraproject FedoraNetapp Bootstrap OS11/4/202417/6/2026
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name…
ModificadaMedia (6.5)1.0%—Google ChromeFedoraproject Fedora10/4/202417/6/2026
Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (6.5)0.79%—Google ChromeFedoraproject Fedora10/4/202417/6/2026
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.6)0.85%—Google ChromeFedoraproject Fedora10/4/202417/6/2026
Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)
ModificadaAlta (7.5)95%—Apache Traffic ServerDebian LinuxFedoraproject Fedora10/4/202417/6/2026
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS…
ModificadaAlta (8.1)1.3%—Ofono Project OfonoFedoraproject Fedora10/4/202417/6/2026
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy…
AnalizadaCrítica (10)20%💥 PoCFedoraproject FedoraRust-lang Rust9/4/202417/6/2026
Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. An attacker able to control the arguments passed to the…
AnalizadaAlta (7.8)85%—LibarchiveFedoraproject FedoraMicrosoft Windows 11 22h2Microsoft Windows 11 23h2+19/4/202417/6/2026
Libarchive Remote Code Execution Vulnerability
ModificadaAlta (7.5)91%💥 PoCApache Http ServerFedoraproject FedoraNetapp Ontap4/4/202417/6/2026
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
AnalizadaMedia (6.3)2.9%—Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.
ModificadaAlta (7.3)3.9%💥 PoCApache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
ModificadaMedia (4.3)0.73%—Nodejs UndiciFedoraproject Fedora4/4/202417/6/2026
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
ModificadaCrítica (9.8)66%💥 ExploitPgadmin 4Fedoraproject Fedora4/4/202417/6/2026
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
ModificadaBaja (3.5)0.80%—Nodejs UndiciFedoraproject Fedora4/4/202417/6/2026
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
ModificadaMedia (5.3)85%—Nghttp2Debian LinuxFedoraproject Fedora4/4/202417/6/2026
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2…
AnalizadaCrítica (9.8)1.2%—UPXFedoraproject Fedora2/4/202417/6/2026
A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055.…
ModificadaAlta (8.2)0.85%—ARM Mbed CryptoARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora29/3/202417/6/2026
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
AnalizadaAlta (8.6)36%—Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+1027/3/202417/6/2026
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.…
AnalizadaBaja (3.5)1.7%—Haxx CurlFedoraproject FedoraApple MacosNetapp Ontap+627/3/202417/6/2026
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled.…
ModificadaAlta (7.7)18%💥 PoCGoogle ChromeFedoraproject Fedora26/3/202417/6/2026
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.5)1.8%—Google ChromeFedoraproject Fedora26/3/202417/6/2026
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.5%—Google ChromeFedoraproject Fedora26/3/202417/6/2026
Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)3.4%—Google ChromeFedoraproject Fedora26/3/202417/6/2026
Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
ModificadaAlta (7.5)1.4%—WiresharkFedoraproject Fedora26/3/202417/6/2026
T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file
AnalizadaMedia (5.4)1.7%—Apache Commons ConfigurationFedoraproject Fedora21/3/202417/6/2026
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.