Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▲ 26 respecto a la semana anterior
Críticas / altas1468▲ 333 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4) | 0.16% | — | Aria2AI | 25/8/2026 | 8/9/2026 | aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function. | |
| Aplazada | Media (6.2) | 0.16% | — | Aria2AI | 24/8/2026 | 8/9/2026 | Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service | |
| Analizada | Media (5.3) | 0.19% | — | Aria2 Project Aria2 | 13/5/2026 | 19/8/2026 | aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication. | |
| Modificada | Alta (7.5) | 3.4% | — | Ziahamza Webui-aria2 | 22/8/2023 | 17/6/2026 | webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability. | |
| Modificada | Alta (7.8) | 0.35% | — | Aria2 Project Aria2Debian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 2/1/2019 | 17/6/2026 | aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file. | |
| Modificada | Media (4.3) | 3.2% | — | Tatsuhiro Tsujikawa Aria2 | 17/5/2010 | 16/6/2026 | Directory traversal vulnerability in aria2 before 1.9.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. | |
| Modificada | Alta (7.6) | 4.9% | — | Tatsuhiro Tsujikawa Aria2 | 20/10/2009 | 16/6/2026 | Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details… | |
| Modificada | Alta (10) | 5.8% | — | Tatsuhiro Tsujikawa Aria2 | 7/10/2009 | 16/6/2026 | Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. |