Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.13% | — | Davisking DlibAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking dlib (dlib/external/zlib modules). This vulnerability is associated with program files inflate.C. This issue affects dlib: before v19.24.9. | |
| Aplazada | Baja (2) | 0.11% | — | Pointcloudlibrary PCLAI | 23/6/2025 | 17/6/2026 | Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib (WITH_SYSTEM_ZLIB=FALSE). | |
| Aplazada | Alta (8.3) | 0.40% | — | Pointcloudlibrary PCLAIZlibAI | 14/5/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user… | |
| Aplazada | Alta (8.7) | 0.46% | — | Davisking DlibAI | 14/5/2025 | 17/6/2026 | Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7. | |
| Analizada | Alta (8.7) | 0.57% | — | Redlib | 20/3/2025 | 17/6/2026 | Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption… | |
| Aplazada | Alta (7.5) | 0.71% | — | Pointcloudlibrary PCLAI | 21/11/2024 | 17/6/2026 | While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to cause a denial-of-service (DoS) attack when processing untrusted PLY files. | |
| Aplazada | Media (5.3) | 1.1% | — | Dingo DlibraAI | 14/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.… | |
| Modificada | Alta (7.5) | 1.4% | — | Springtree Madlib-object-utils | 15/4/2022 | 17/6/2026 | The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676) | |
| Modificada | Crítica (9.8) | 3.0% | — | Bdew Bdlib | 3/6/2021 | 17/6/2026 | The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization. | |
| Modificada | Crítica (9.8) | 2.1% | — | Springtree Madlib-object-utils | 14/8/2020 | 17/6/2026 | madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue. | |
| Modificada | Crítica (9.8) | 1.7% | — | Monetra Mstdlib | 13/7/2018 | 17/6/2026 | mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) during a copy operation, related to fs/m_fs.c and fs/m_fs_path.c. An attacker could create the file and then would have… | |
| Modificada | Media (6.5) | 1.6% | — | Puppet Stdlib | 16/1/2015 | 17/6/2026 | The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache. | |
| Modificada | Media (4.3) | 2.3% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected value of None for the address, or an ECONNABORTED,… | |
| Modificada | Media (4) | 1.7% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Memory leak in the on_dtp_close function in ftpserver.py in pyftpdlib before 0.5.2 allows remote authenticated users to cause a denial of service (memory consumption) by sending a QUIT command during a data transfer. | |
| Modificada | Media (4) | 1.0% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session. | |
| Modificada | Media (4.3) | 0.92% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the getpeername function having an ENOTCONN error, a different vulnerability than CVE-2010-3494. | |
| Modificada | Media (4.3) | 1.4% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, a different vulnerability than… | |
| Modificada | Media (4) | 1.3% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt. | |
| Modificada | Alta (7.5) | 1.5% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (6.5) | 2.0% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involving a symlink in a pathname to a (1) CWD, (2) DELE, (3) STOR, or (4) RETR command. | |
| Modificada | Media (6.5) | 1.8% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of the connection from the FTP client, which might allow remote authenticated users to conduct FTP bounce attacks via crafted FTP data, as… | |
| Modificada | Media (4) | 1.7% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | The ftp_STOU function in FTPServer.py in pyftpdlib before 0.2.0 does not limit the number of attempts to discover a unique filename, which might allow remote authenticated users to cause a denial of service via a STOU command. | |
| Modificada | Media (5) | 2.2% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | FTPServer.py in pyftpdlib before 0.2.0 allows remote attackers to cause a denial of service via a long command. | |
| Modificada | Media (5) | 1.1% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command. | |
| Modificada | Alta (7.5) | 2.1% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack. |