Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.55% | — | RXI MicrotarAI | 17/6/2026 | 10/8/2026 | A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source. | |
| Aplazada | Alta (8.7) | 0.75% | — | RXI MicrotarAI | 17/6/2026 | 10/8/2026 | An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next computes the offset to the next record as round_up(h.size, 512) + sizeof(mtar_raw_header_t)… | |
| Aplazada | Baja (1.9) | 0.16% | — | RXI FEAI | 12/3/2026 | 17/6/2026 | A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. The impacted element is the function read_ of the file src/fe.c. This manipulation with the input 1 causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. This… | |
| Aplazada | Alta (7.1) | 0.29% | — | Beiyuouo Arxiv-dailyAI | 15/7/2025 | 17/6/2026 | Directory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing the the topic.yml file in the generation logic in daily_arxiv.py. | |
| Modificada | Alta (7.5) | 3.4% | — | GE Pacsystems Rx3i Cpe305 FirmwareGE Pacsystems Rx3i Cpe310 FirmwareGE Rx3i Cpe330 FirmwareGE Rx3i CPE 400 Firmware+4 | 18/5/2018 | 17/6/2026 | In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially… | |
| Modificada | Alta (7.5) | 3.9% | — | Ashley Montanaro Darxite | 14/11/2000 | 16/6/2026 | Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password. |