Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.35% | — | LibexpatAI | 29/9/2026 | 29/9/2026 | libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service. | |
| Analizada | Alta (7.8) | 0.11% | — | Libexpat Project Libexpat | 20/8/2026 | 8/9/2026 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. | |
| Analizada | Alta (7.5) | 0.29% | — | Libexpat Project Libexpat | 20/8/2026 | 8/9/2026 | In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content. | |
| Analizada | Alta (8.7) | 0.74% | — | Libexpat Project Libexpat | 18/8/2026 | 18/9/2026 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote… | |
| Aplazada | Media (6.2) | 0.19% | — | LibexpatAI | 10/8/2026 | 31/8/2026 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. | |
| Analizada | Media (5.9) | 0.18% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219. | |
| Analizada | Media (6.9) | 0.13% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | |
| Analizada | Media (6.9) | 0.13% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | |
| Analizada | Media (6.5) | 0.12% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | |
| Analizada | Media (6.9) | 0.13% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | libexpat before 2.8.2 has an integer overflow in copyString. | |
| Analizada | Media (6.9) | 0.17% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. | |
| Analizada | Media (6.9) | 0.17% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. | |
| Analizada | Media (6.9) | 0.13% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | libexpat before 2.8.2 has an integer overflow in getAttributeId. | |
| Analizada | Media (6.9) | 0.13% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | libexpat before 2.8.2 has an integer overflow in addBinding. | |
| Analizada | Media (6.9) | 0.17% | — | Libexpat Project Libexpat | 21/6/2026 | 23/6/2026 | libexpat before 2.8.2 has an integer overflow in storeAtts. | |
| Analizada | Media (6.9) | 0.10% | — | Libexpat Project Libexpat | 19/6/2026 | 23/6/2026 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. | |
| Analizada | Media (4.9) | 0.18% | — | Libexpat Project Libexpat | 19/6/2026 | 23/6/2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). | |
| Analizada | Media (5.9) | 0.18% | — | Libexpat Project Libexpat | 4/6/2026 | 22/7/2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, | |
| Modificada | Alta (7.5) | 0.48% | — | Libexpat Project Libexpat | 10/5/2026 | 16/9/2026 | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. | |
| Modificada | Baja (2.9) | 0.40% | — | Libexpat Project Libexpat | 16/4/2026 | 14/7/2026 | libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. | |
| Modificada | Media (5.5) | 0.16% | — | Libexpat Project Libexpat | 16/3/2026 | 14/7/2026 | libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition. | |
| Modificada | Media (5.5) | 0.17% | — | Libexpat Project Libexpat | 16/3/2026 | 14/7/2026 | libexpat before 2.7.5 allows an infinite loop while parsing DTD content. | |
| Modificada | Media (5.5) | 0.16% | — | Libexpat Project Libexpat | 16/3/2026 | 14/7/2026 | libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. | |
| Modificada | Alta (7.8) | 0.21% | — | Libexpat Project Libexpat | 30/1/2026 | 17/6/2026 | In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation. | |
| Modificada | Baja (2.5) | 0.19% | — | Libexpat Project Libexpat | 23/1/2026 | 17/6/2026 | In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. |