Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.24% | — | GNU Binutils | 27/7/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is… | |
| Modificada | Baja (1.9) | 0.24% | — | GNU Binutils | 27/7/2025 | 17/6/2026 | A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has… | |
| Aplazada | Media (5.9) | 0.19% | — | GNU C LibraryAI | 23/7/2025 | 17/6/2026 | The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the… | |
| Aplazada | Media (4.8) | 0.13% | — | Opensuse Mailman3AIGNU LogrotateAI | 23/7/2025 | 17/6/2026 | A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP to arbitrary processes. This issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1. | |
| Aplazada | Alta (8.6) | 0.16% | — | Signum-net FaraAI | 21/7/2025 | 17/6/2026 | Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: through 5.0.80.34. | |
| Analizada | Baja (2) | 0.25% | — | SIR Gnuboard | 18/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component Post Reply Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Modificada | Baja (1.9) | 0.19% | — | GNU Binutils | 13/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the… | |
| Modificada | Baja (1.9) | 0.29% | 💥 PoC | GNU Binutils | 13/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (4.1) | 0.49% | — | GNU TAR | 11/7/2025 | 17/6/2026 | GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative… | |
| Aplazada | Media (6.5) | 0.72% | — | GnutlsAI | 10/7/2025 | 1/9/2026 | A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite(). | |
| Modificada | Alta (8.2) | 0.83% | — | GnutlsRedhat Openshift Container PlatformRedhat Enterprise Linux | 10/7/2025 | 1/9/2026 | A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service… | |
| Modificada | Media (5.3) | 1.4% | — | GnutlsRedhat Openshift Container PlatformRedhat Enterprise Linux | 10/7/2025 | 1/9/2026 | A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that… | |
| Modificada | Alta (8.2) | 1.4% | — | GnutlsRedhat Openshift Container PlatformRedhat Enterprise Linux | 10/7/2025 | 1/9/2026 | A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own,… | |
| Analizada | Media (6.1) | 0.24% | — | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php. | |
| Analizada | Media (6.1) | 0.24% | — | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component. | |
| Analizada | Media (6.1) | 0.52% | 💥 Exploit | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php. | |
| Aplazada | Media (6.5) | 0.28% | — | Gnuget MF Plus WpmlAI | 4/7/2025 | 17/6/2026 | Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MF Plus WPML: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.1) | 2.4% | 💥 Exploit | Bitto.kazi Custom Login AND Signup WidgetAI | 1/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.17% | — | UI Ucrm Client Signup PluginAI | 29/6/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default. | |
| Aplazada | Media (5.6) | 0.14% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Baja (3.2) | 0.17% | — | Nixos NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before… | |
| Aplazada | Baja (3.2) | 0.17% | — | Nixos NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This… | |
| Aplazada | Baja (2.9) | 0.18% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Baja (3.2) | 0.14% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Media (4.8) | 0.20% | — | GNU NcursesAI | 16/6/2025 | 17/6/2026 | A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version… |