Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.40%—Hickory-resolverAI18/9/202622/9/2026
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records…
AplazadaAlta (8.7)0.85%—Resolver PerspectiveAI4/8/20269/9/2026
Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass the insufficient query-string-stripping sanitization to traverse outside the…
AplazadaAlta (7.1)0.52%—Resolver PerspectiveAI4/8/20269/9/2026
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an…
AplazadaAlta (8.7)0.29%—Resolver PerspectiveAI4/8/20269/9/2026
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or…
AplazadaMedia (5.1)0.26%—Resolver PerspectiveAI4/8/20269/9/2026
Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unescaped HTML markup, which are interpolated directly into innerHTML during CSV serialization rendering. Attackers can…
AplazadaAlta (8.7)1.2%—Resolver PerspectiveAI4/8/20269/9/2026
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={}…
AplazadaAlta (8.1)0.62%—Knot ResolverAI25/7/202630/7/2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
AplazadaAlta (7.5)0.49%—FlaresolverrAI20/7/202621/7/2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information
AplazadaAlta (8.9)0.63%—Intlify Message ResolverAIIntlify VUE I18n CoreAIVuejs VUE I18nAI7/3/202517/6/2026
Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype…
AplazadaAlta (8.3)0.42%—Apphp Js-object-resolverAI17/6/202417/6/2026
apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.
ModificadaAlta (7.5)100%—Redhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+914/2/202417/6/2026
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the…
ModificadaAlta (7.5)1.3%—Apache Sling Servlets Resolver6/2/202417/6/2026
Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system. If the system is vulnerable,…
ModificadaAlta (7.5)0.64%—NIC Knot Resolver22/10/202317/6/2026
Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.
ModificadaAlta (7.5)0.71%—NIC Knot Resolver21/2/202317/6/2026
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.
ModificadaAlta (7.5)0.24%—Go-resolver Project Go-resolver28/12/202217/6/2026
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.
ModificadaMedia (6.5)0.23%—Go-resolver Project Go-resolver28/12/202217/6/2026
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain.
ModificadaAlta (7.5)1.9%—NIC Knot ResolverFedoraproject FedoraDebian Linux23/9/202217/6/2026
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
ModificadaMedia (5.3)0.74%—NIC Knot Resolver20/6/202217/6/2026
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.
ModificadaAlta (7.5)1.4%—NIC Knot Resolver25/8/202117/6/2026
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
ModificadaCrítica (9.8)2.9%—Pac-resolver Project Pac-resolver24/8/202117/6/2026
This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.
ModificadaAlta (7.5)1.2%—NIC Knot Resolver30/3/202117/6/2026
A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.
ModificadaAlta (7.5)2.6%—NIC Knot Resolver19/5/202017/6/2026
Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
ModificadaMedia (5.9)0.78%—Postfix-mta-sts-resolver Project Postfix-mta-sts-resolver22/1/202017/6/2026
In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.
ModificadaAlta (7.5)2.2%—NIC Knot ResolverDebian Linux16/12/201917/6/2026
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed…
ModificadaMedia (5.9)3.5%—ISC BindNlnetlabs NSDNIC Knot ResolverRedhat Enterprise Linux5/11/201916/6/2026
Cache Poisoning issue exists in DNS Response Rate Limiting.