Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

6914 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)0.67%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.
ModificadaAlta (7.5)0.90%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time,…
ModificadaCrítica (9.8)0.41%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.
ModificadaMedia (6.1)0.47%—MediawikiFedoraproject Fedora5/5/202417/6/2026
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.
ModificadaMedia (5.9)1.3%—Uriparser Project UriparserFedoraproject Fedora3/5/202417/6/2026
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
ModificadaAlta (8.6)1.2%—Uriparser Project UriparserFedoraproject Fedora3/5/202417/6/2026
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
AnalizadaAlta (7.5)1.1%—Rjbs Email-mimeFedoraproject Fedora2/5/202417/6/2026
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
AnalizadaMedia (5.4)0.46%—Pgadmin 4Fedoraproject Fedora2/5/202417/6/2026
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
AnalizadaAlta (8.8)0.63%—Pgadmin 4Fedoraproject Fedora2/5/202417/6/2026
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL…
ModificadaCrítica (9.8)1.4%—Nothings STB Vorbis.cFedoraproject Fedora1/5/202417/6/2026
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (8.8)1.1%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)1.2%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.5)1.0%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.5)0.90%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)9.0%—Google ChromeFedoraproject Fedora1/5/202417/6/2026
Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
ModificadaAlta (7.8)0.18%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: Binding devm_led_classdev_register() to the netdev is problematic because on module removal we get a RTNL-related deadlock. Fix this by avoiding the device-managed LED functions. Note: We can safely call led_classdev_unregister() for a LED even if…
ModificadaMedia (4.7)0.21%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() nft_unregister_obj() can concurrent with __nft_obj_type_get(), and there is not any protection when iterate over nf_tables_objects list in __nft_obj_type_get(). Therefore, there is…
ModificadaAlta (7.8)0.64%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip conntrack input hook for promisc packets For historical reasons, when bridge device is in promisc mode, packets that are directed to the taps follow bridge input hook path. This patch adds a workaround to reset conntrack…
ModificadaMedia (5.5)0.29%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view on netlink dump The generation mask can be updated while netlink dump is in progress. The pipapo set backend walk iterator cannot rely on it to infer what view of the datastructure is to be used. Add…
ModificadaMedia (5.5)0.34%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate pppoe header Ensure there is sufficient room to access the protocol field of the PPPoe header. Validate it once before the flowtable lookup, then use a helper function to access protocol field.
ModificadaMedia (5.5)0.23%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect pppoe tuple pppoe traffic reaching ingress path does not match the flowtable entry because the pppoe header is expected to be at the network header offset. This bug causes a mismatch in the flow table lookup, so pppoe…
ModificadaMedia (5.5)0.18%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Prevent deadlock while disabling aRFS When disabling aRFS under the `priv->state_lock`, any scheduled aRFS works are canceled using the `cancel_work_sync` function, which waits for the work to end if it has already started. However, while…
ModificadaMedia (5.5)0.27%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: tun: limit printing rate when illegal packet received by tun dev vhost_worker will call tun call backs to receive packets. If too many illegal packets arrives, tun_do_read will keep dumping packet contents. When console is enabled, it will costs much…
ModificadaMedia (5.5)0.27%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: restore set elements when delete set fails From abort path, nft_mapelem_activate() needs to restore refcounters to the original state. Currently, it uses the set->ops->walk() to iterate over these set elements. The existing set…
AnalizadaAlta (7.8)0.30%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: drm: nv04: Fix out of bounds access When Output Resource (dcb->or) value is assigned in fabricate_dcb_output(), there may be out of bounds access to dac_users array in case dcb->or is zero because ffs(dcb->or) is used as index there. The 'or' argument…