Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.88%—Irontec SngrepAI12/9/202623/9/2026
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute…
AplazadaMedia (4.8)0.12%—UgrepAI5/9/202623/9/2026
ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.
AplazadaBaja (1.1)0.08%—Yoanbernabeu GrepaiAIPostgresqlAI8/6/202623/7/2026
A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be…
AplazadaBaja (1.3)0.16%—Yoanbernabeu GrepaiAIQdrantAI8/6/202623/7/2026
A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is…
AplazadaMedia (5.5)2.2%—Vetcoders MCP Server SemgrepAI30/4/202617/6/2026
A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack…
AplazadaMedia (4.1)0.19%—Openai Codex CLIAIRipgrepAI25/7/202517/6/2026
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.
AnalizadaAlta (8.6)2.4%⚠ Explotación activaReviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+219/3/202517/6/2026
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be…
AnalizadaAlta (7.5)0.61%—Irontec Sngrep29/5/202417/6/2026
Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet.
AnalizadaCrítica (9.8)1.9%—Irontec Sngrep10/4/202417/6/2026
A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' headers into fixed-size buffers in the sip_validate_packet and sip_parse_extra_headers functions within src/sip.c. This vulnerability allows…
AnalizadaCrítica (9.8)1.8%—Irontec Sngrep10/4/202417/6/2026
A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and sip_get_xcallid in sip.c use the strncpy function to copy header contents into fixed-size buffers without checking the data length. This…
ModificadaAlta (7.8)0.31%—Irontec Sngrep23/6/202317/6/2026
Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c.
ModificadaAlta (7.8)0.31%—Irontec Sngrep9/5/202317/6/2026
Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c.
ModificadaAlta (7.8)0.31%—Irontec Sngrep9/5/202317/6/2026
Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.
ModificadaAlta (7.5)1.1%—Bingrep Project Bingrep21/1/202217/6/2026
Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).
ModificadaCrítica (9.8)1.9%—Ripgrep Project Ripgrep11/6/202117/6/2026
ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.
ModificadaBaja (2.1)0.49%—GNU GrepOpensuse12/2/201517/6/2026
The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.
ModificadaMedia (6.8)3.1%—Beyondgrep ACK14/12/201317/6/2026
ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched.
ModificadaMedia (4.4)1.0%—GNU Grep3/1/201316/6/2026
Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.
ModificadaMedia (5)2.1%—Oscar Nierstrasz Htgrep14/11/200016/6/2026
Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.