Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.71%—Erofs-utils Project Erofs-utils1/6/202317/6/2026
Heap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.
ModificadaAlta (7.8)0.81%—Erofs-utils Project Erofs-utils1/6/202317/6/2026
Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.
ModificadaCrítica (9.8)0.99%—Antfu Utils30/5/202317/6/2026
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
ModificadaMedia (6.5)0.90%—GNU Binutils17/5/202317/6/2026
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
ModificadaAlta (7.8)0.49%—GNU Binutils3/4/202317/6/2026
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
ModificadaMedia (5.5)0.17%—Opensuse Supportutils15/2/202317/6/2026
A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise…
ModificadaMedia (5.5)0.44%—GNU BinutilsFedoraproject FedoraRedhat Enterprise Linux27/1/202317/6/2026
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
ModificadaCrítica (9.8)0.81%—Globalpom-utils Project Globalpom-utils6/1/202317/6/2026
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.java. The manipulation leads to…
ModificadaCrítica (9.8)0.66%—Opensim-utils Project Opensim-utils6/1/202317/6/2026
A vulnerability, which was classified as critical, has been found in jeff-kelley opensim-utils. Affected by this issue is the function DatabaseForRegion of the file regionscrits.php. The manipulation of the argument region leads to sql injection. The patch is identified as c29e5c729a833a29dbf5b1e505a0553fe154575e. It…
ModificadaMedia (4.2)0.59%—Amazon Efs-utilsAmazon Elastic File System Container Storage Interface Driver28/12/202217/6/2026
efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to…
ModificadaCrítica (9.1)1.4%—Goutils Project Goutils27/12/202217/6/2026
Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.
ModificadaCrítica (9.1)1.1%—Tar-utils Project Tar-utils27/12/202217/6/2026
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
ModificadaMedia (5.3)0.47%—Utils Project Utils25/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from observable state. The name of the patch is…
ModificadaAlta (7.4)0.68%—Freedesktop Xdg-utils19/11/202217/6/2026
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
ModificadaAlta (7.5)2.2%—Webpack.js Loader-utils14/10/202217/6/2026
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
ModificadaCrítica (9.8)2.9%—Webpack.js Loader-utilsDebian Linux12/10/202217/6/2026
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
ModificadaAlta (7.5)2.2%—Webpack.js Loader-utils11/10/202217/6/2026
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
ModificadaAlta (7.5)2.1%—GNU InetutilsMIT Kerberos 5Debian LinuxNetkit-telnet Project Netkit-telnet30/8/202217/6/2026
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many…
ModificadaAlta (8.8)78%—Zohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSP+229/8/202217/6/2026
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
ModificadaMedia (4.9)1.7%—Openstack Oslo.utilsRedhat Openshift Container PlatformRedhat Openstack PlatformDebian Linux29/8/202217/6/2026
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
ModificadaMedia (5.5)0.33%—GNU BinutilsFedoraproject Fedora26/8/202217/6/2026
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
ModificadaAlta (8.8)80%—Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+310/8/202217/6/2026
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.
AnalizadaAlta (7.5)7.3%💥 ExploitZohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+310/8/202217/6/2026
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
ModificadaCrítica (9.8)3.3%—Ssl-utils Project Ssl-utils2/6/202217/6/2026
OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.
ModificadaCrítica (9.8)4.4%—Apache Maven Shared UtilsDebian Linux23/5/202217/6/2026
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.