Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2631▼ 309 respecto a la semana anterior
Críticas / altas1352▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.41% | — | TAR Project TAR | 20/3/2026 | 17/6/2026 | tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink… | |
| Aplazada | Media (4) | 0.13% | — | Notaryproject Notation-goAI | 13/1/2025 | 17/6/2026 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp… | |
| Analizada | Baja (3.3) | 0.19% | — | Notaryproject Notation-go | 13/1/2025 | 17/6/2026 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check feature. After retrieving the CRL, notation-go attempts to update the… | |
| Modificada | Media (6.8) | 0.29% | — | Notaryproject Notation-go | 19/1/2024 | 17/6/2026 | The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts. An external actor with control of a compromised container registry can provide outdated versions of OCI artifacts, such… | |
| Modificada | Alta (8.8) | 0.35% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above. Users unable to upgrade… | |
| Modificada | Media (6.5) | 0.48% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation verify command on the same machine. The problem has been fixed in… | |
| Modificada | Media (5.7) | 0.51% | — | Notaryproject Notation-go | 6/6/2023 | 17/6/2026 | notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation inspect command on the same machine. The problem has been fixed… | |
| Modificada | Alta (7.5) | 0.44% | — | Notaryproject Notation-go | 20/2/2023 | 17/6/2026 | notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The application will be killed, and thus availability is impacted. The problem has… | |
| Modificada | Media (5.3) | 1.1% | — | Awful-salmonella-tar Project Awful-salmonella-tar | 18/2/2022 | 17/6/2026 | A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories. | |
| Modificada | Alta (7.5) | 1.4% | — | TAR Project TAR | 10/8/2021 | 17/6/2026 | An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal. | |
| Modificada | Alta (8.1) | 15% | — | TAR Project TAROracle GraalvmSiemens Sinec Infrastructure Network Services | 3/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths`… | |
| Modificada | Alta (8.1) | 7.8% | — | TAR Project TAROracle GraalvmSiemens Sinec Infrastructure Network Services | 3/8/2021 | 17/6/2026 | The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by… | |
| Modificada | Crítica (9.8) | 1.5% | — | Centurystar Project Centurystar | 8/1/2020 | 17/6/2026 | centurystar 7.12 ActiveX Control has a Stack Buffer Overflow | |
| Modificada | Alta (7.5) | 1.7% | — | TAR Project TAR | 26/8/2019 | 17/6/2026 | An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive. | |
| Modificada | Alta (7.5) | 0.99% | — | Nectar Project Nectar | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for Nectar (NCTR), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. |