Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 272 respecto a la semana anterior
Críticas / altas1349▲ 92 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.21%—Amazon Firecracker8/4/202624/7/2026
An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration…
AnalizadaMedia (6)0.22%—Amazon Firecracker23/1/202617/6/2026
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the…
AnalizadaAlta (7.8)0.45%—J4k0xb Webcrack15/8/202417/6/2026
webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles feature in conjunction with the saving feature. If a module…
ModificadaCrítica (9.8)1.2%—Pdfcrack Project Pdfcrack6/7/202317/6/2026
An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.
ModificadaMedia (5.4)0.89%—Technocrackers Bulk Price Update FOR Woocommerce22/3/202317/6/2026
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.
ModificadaAlta (7.5)1.7%—Amazon Firecracker16/10/202017/6/2026
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
ModificadaMedia (5.9)1.7%—Amazon Firecracker4/8/202017/6/2026
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is…
ModificadaAlta (8.8)2.4%—Netcracker Resource Management System8/2/202017/6/2026
Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3, (8) param4, (9) filter_INSERT_COUNT, (10) filter_MINOR_FALLOUT,…
ModificadaMedia (5.4)0.94%—Netcracker Resource Management System8/2/202017/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) ctrl, (2) t90001_0_theform_selection, (3) _scroll, (4) tableName, (5) parent, (6) circuit, (7) return, (8) xname, or (9)…
ModificadaCrítica (9.8)24%—Aircrack-ng31/1/202017/6/2026
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
ModificadaAlta (7.8)0.81%—Aircrack-ng31/1/202017/6/2026
Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.
ModificadaCrítica (9.8)3.3%—Amazon Firecracker11/12/201917/6/2026
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.
ModificadaAlta (7.5)4.2%—Aircrack-ng17/10/201717/6/2026
network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted length parameter.
ModificadaAlta (7.5)3.3%—Aircrack-ng17/10/201717/6/2026
buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted length parameter.
ModificadaAlta (7.5)2.5%—Sipcrack Project Sipcrack26/7/201717/6/2026
A memory leak was found in the way SIPcrack 0.2 handled processing of SIP traffic, because a lines array was mismanaged. A remote attacker could potentially use this flaw to crash long-running sipdump network sniffing sessions.
ModificadaMedia (5.9)2.0%—Sipcrack Project Sipcrack26/7/201717/6/2026
An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishandled. A remote attacker could potentially use this flaw to crash the sipdump process by generating specially crafted SIP traffic.
ModificadaAlta (7.8)0.74%—Cracklib Project CracklibOpensuse LeapDebian Linux7/9/201617/6/2026
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
ModificadaMedia (6.8)7.3%—Aircrack-ngGentoo Linux28/10/201316/6/2026
Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL packet.
ModificadaAlta (7.5)5.0%—John Nunemaker Crack9/4/201316/6/2026
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2)…
ModificadaMedia (6.8)0.89%—Supercrackmunkey Simpleloginsys18/3/201016/6/2026
SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (10)19%—Aircrack-ng Airodump-ng18/4/200716/6/2026
Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 allows remote attackers to execute arbitrary code via crafted 802.11 authentication packets.
ModificadaMedia (5)3.1%—Crackalaka9/4/200416/6/2026
The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.
ModificadaBaja (2.1)0.35%—L0phtcrack6/1/199916/6/2026
L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.
ModificadaMedia (5)1.3%—L0phtcrack1/12/199816/6/2026
Remote attackers can perform a denial of service using IRIX fcagent.
ModificadaAlta (7.2)0.43%—Alec Muffet Cracklib14/12/199716/6/2026
Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.