Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.6) | 0.21% | — | Pcre2AI | 30/9/2026 | 3/10/2026 | PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data. | |
| En análisis | Baja (3.3) | 0.16% | — | Pcre2 | 11/9/2026 | 16/9/2026 | In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. | |
| En análisis | Alta (7.8) | 0.13% | — | Pcre2 | 11/9/2026 | 16/9/2026 | In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. | |
| Analizada | Media (6.5) | 0.27% | — | Pcre2 | 11/9/2026 | 16/9/2026 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject. | |
| Analizada | Media (6.5) | 0.25% | — | Pcre2 | 11/9/2026 | 16/9/2026 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. | |
| Analizada | Alta (7.4) | 0.28% | — | Pcre2 | 11/9/2026 | 16/9/2026 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. | |
| Analizada | Media (5.9) | 0.29% | — | Pcre2 | 11/9/2026 | 16/9/2026 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. | |
| Aplazada | Alta (8.2) | 0.39% | — | Pcre2AI | 5/9/2026 | 9/9/2026 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a… | |
| Analizada | Media (6.9) | 0.80% | — | Pcre2 | 27/8/2025 | 17/6/2026 | The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in… | |
| Modificada | Alta (7.5) | 1.1% | — | Pcre2 | 18/7/2023 | 17/6/2026 | Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input. | |
| Modificada | Crítica (9.1) | 2.8% | — | Pcre2Redhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+8 | 16/5/2022 | 17/6/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers. | |
| Analizada | Crítica (9.1) | 3.4% | — | Pcre2Fedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+9 | 16/5/2022 | 17/6/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching… | |
| Modificada | Alta (7.5) | 1.6% | — | Pcre2Fedoraproject FedoraSplunk Universal Forwarder | 14/2/2020 | 17/6/2026 | An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in… | |
| Modificada | Crítica (9.8) | 4.1% | — | Pcre2 | 5/5/2017 | 17/6/2026 | pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression. | |
| Modificada | Crítica (9.8) | 3.1% | — | Pcre2 | 1/5/2017 | 17/6/2026 | PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures." | |
| Modificada | Alta (7.5) | 5.0% | — | PcrePcre2 | 20/3/2017 | 17/6/2026 | libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup. | |
| Modificada | Alta (7.5) | 6.2% | — | Pcre2PcreIBM Powerkvm | 13/12/2016 | 17/6/2026 | PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/. | |
| Modificada | Crítica (9.8) | 9.2% | — | Pcre2Pcre | 13/12/2016 | 17/6/2026 | Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384. | |
| Modificada | Crítica (9.8) | 8.4% | — | PcrePcre2 | 17/3/2016 | 17/6/2026 | The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer… |