Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.17% | — | Musl LibcAI | 10/4/2026 | 17/6/2026 | An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo… | |
| Aplazada | Media (4.8) | 0.16% | — | Musl LibcAI | 10/4/2026 | 17/6/2026 | A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is… | |
| Analizada | Alta (7) | 0.35% | — | Musl-libc Musl | 14/2/2025 | 17/6/2026 | musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8. | |
| Aplazada | Media (6.4) | 0.34% | — | Muslim Prayer Time Salah IqamahAI | 9/1/2025 | 17/6/2026 | The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Analizada | Alta (7.6) | 0.26% | — | Realwebcare Muslim Prayer Time BD | 26/6/2024 | 17/6/2026 | The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |
| Modificada | Media (5.5) | 0.65% | — | Musl-libc MuslDebian LinuxFedoraproject FedoraOracle Graalvm | 24/11/2020 | 17/6/2026 | In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). | |
| Modificada | Crítica (9.8) | 2.2% | — | Musl-libc Musl | 20/2/2020 | 17/6/2026 | Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service (crash) via an invalid name length in a… | |
| Modificada | Crítica (9.8) | 2.5% | — | Musl-libc Musl | 6/8/2019 | 17/6/2026 | musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code. | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter. | |
| Modificada | Alta (7.2) | 1.1% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php. | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter. | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter. | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter. | |
| Modificada | Alta (8.8) | 0.94% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter. | |
| Modificada | Media (6.8) | 0.40% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php. | |
| Modificada | Media (5.4) | 0.49% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter. | |
| Modificada | Crítica (9.8) | 2.2% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 13/12/2017 | 17/6/2026 | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Musl-libc Musl | 19/10/2017 | 17/6/2026 | musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dns_parse_callback in network/lookup_name.c does not restrict the number of addresses, and thus an attacker can provide an unexpected number by sending A records in a reply to an AAAA query. | |
| Modificada | Crítica (9.8) | 2.2% | — | Musl-libc Musl | 18/8/2017 | 17/6/2026 | Stack-based buffer overflow in the inet_pton function in network/inet_pton.c in musl libc 0.9.15 through 1.0.4, and 1.1.0 through 1.1.7 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 3.4% | — | Etalabs Musl | 13/2/2017 | 17/6/2026 | Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write. | |
| Modificada | Media (5.4) | 0.27% | — | Zillionmuslims Zillion Muslims | 21/10/2014 | 17/6/2026 | The Zillion Muslims (aka com.zillionmuslims.src) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.4% | — | Etalabs Musl | 31/8/2012 | 16/6/2026 | Stack-based buffer overflow in fprintf in musl before 0.8.8 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string to an unbuffered stream such as stderr. |