Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2631▼ 309 respecto a la semana anterior
Críticas / altas1352▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.41%—TAR Project TAR20/3/202617/6/2026
tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink…
AplazadaMedia (4)0.13%—Notaryproject Notation-goAI13/1/202517/6/2026
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp…
AnalizadaBaja (3.3)0.19%—Notaryproject Notation-go13/1/202517/6/2026
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check feature. After retrieving the CRL, notation-go attempts to update the…
ModificadaMedia (6.8)0.29%—Notaryproject Notation-go19/1/202417/6/2026
The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts. An external actor with control of a compromised container registry can provide outdated versions of OCI artifacts, such…
ModificadaAlta (8.8)0.35%—Notaryproject Notation-go6/6/202317/6/2026
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgrade their notation-go library to v1.0.0-rc.6 or above. Users unable to upgrade…
ModificadaMedia (6.5)0.48%—Notaryproject Notation-go6/6/202317/6/2026
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation verify command on the same machine. The problem has been fixed in…
ModificadaMedia (5.7)0.51%—Notaryproject Notation-go6/6/202317/6/2026
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of signatures to an artifact can cause denial of service of services on the machine, if a user runs notation inspect command on the same machine. The problem has been fixed…
ModificadaAlta (7.5)0.44%—Notaryproject Notation-go20/2/202317/6/2026
notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The application will be killed, and thus availability is impacted. The problem has…
ModificadaMedia (5.3)1.1%—Awful-salmonella-tar Project Awful-salmonella-tar18/2/202217/6/2026
A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.
ModificadaAlta (7.5)1.4%—TAR Project TAR10/8/202117/6/2026
An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.
ModificadaAlta (8.1)15%—TAR Project TAROracle GraalvmSiemens Sinec Infrastructure Network Services3/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths`…
ModificadaAlta (8.1)7.8%—TAR Project TAROracle GraalvmSiemens Sinec Infrastructure Network Services3/8/202117/6/2026
The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by…
ModificadaCrítica (9.8)1.5%—Centurystar Project Centurystar8/1/202017/6/2026
centurystar 7.12 ActiveX Control has a Stack Buffer Overflow
ModificadaAlta (7.5)1.7%—TAR Project TAR26/8/201917/6/2026
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
ModificadaAlta (7.5)0.99%—Nectar Project Nectar5/7/201817/6/2026
The sell function of a smart contract implementation for Nectar (NCTR), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.