Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.54% | — | Pcre | 21/3/2019 | 17/6/2026 | In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used | |
| Modificada | Media (6.1) | 1.0% | — | Snapcreek Duplicator | 14/11/2017 | 17/6/2026 | installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly. | |
| Modificada | Alta (8.2) | 7.5% | 💥 Exploit | Snapcreek Duplicator | 7/8/2017 | 17/6/2026 | The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. | |
| Modificada | Alta (7.5) | 3.1% | — | Pcre | 11/7/2017 | 17/6/2026 | In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression. | |
| Modificada | Crítica (9.8) | 4.1% | — | Pcre2 | 5/5/2017 | 17/6/2026 | pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression. | |
| Modificada | Crítica (9.8) | 3.1% | — | Pcre2 | 1/5/2017 | 17/6/2026 | PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures." | |
| Modificada | Alta (7.8) | 2.6% | — | Pcre | 23/3/2017 | 17/6/2026 | Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Alta (7.8) | 2.4% | — | Pcre | 23/3/2017 | 17/6/2026 | Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Media (5.5) | 2.0% | — | Pcre | 23/3/2017 | 17/6/2026 | The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file. | |
| Modificada | Alta (7.5) | 5.0% | — | PcrePcre2 | 20/3/2017 | 17/6/2026 | libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup. | |
| Modificada | Alta (7.5) | 4.5% | — | Pcre | 16/2/2017 | 17/6/2026 | The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression. | |
| Modificada | Crítica (9.1) | 7.7% | — | IBM PowerkvmPcre | 13/12/2016 | 17/6/2026 | Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing… | |
| Modificada | Alta (7.5) | 6.2% | — | Pcre2PcreIBM Powerkvm | 13/12/2016 | 17/6/2026 | PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/. | |
| Modificada | Crítica (9.8) | 9.2% | — | Pcre2Pcre | 13/12/2016 | 17/6/2026 | Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384. | |
| Modificada | Alta (7.3) | 2.4% | — | Pcre | 28/3/2016 | 17/6/2026 | pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a crafted string, as demonstrated by packets encountered by Suricata during use of a… | |
| Modificada | Crítica (9.8) | 8.4% | — | PcrePcre2 | 17/3/2016 | 17/6/2026 | The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer… | |
| Modificada | Crítica (9.8) | 7.8% | — | PcrePHPFedoraproject FedoraOracle Solaris | 3/1/2016 | 17/6/2026 | The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service… | |
| Modificada | Alta (7.5) | 3.5% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8392. | |
| Modificada | Crítica (9.8) | 4.8% | — | Pcre Perl Compatible Regular Expression LibraryPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 4.4% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client. | |
| Modificada | Alta (7.5) | 3.6% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a… | |
| Modificada | Crítica (9.8) | 6.4% | — | PcreOracle LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+6 | 2/12/2015 | 17/6/2026 | The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 4.7% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 3.9% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 6.6% | — | Oracle LinuxPcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp… |