Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.55%—Technitium DNS ServerAI26/6/20265/7/2026
An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components
Pendiente de análisisMedia (6.9)0.51%—Technitium DNS ServerAI19/5/202624/7/2026
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0.
Pendiente de análisisCrítica (9.1)0.45%—Dual Dhcp DNS ServerAI7/4/202624/7/2026
Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject forged responses…
ModificadaAlta (7.5)0.69%—Technitium DNS Server13/1/202317/6/2026
Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.
ModificadaCrítica (9.8)0.72%—Technitium DNS Server21/11/202217/6/2026
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful,…
ModificadaCrítica (9.8)0.72%—Technitium DNS Server21/11/202217/6/2026
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful,…
ModificadaAlta (8.1)1.2%—Synology DNS Server28/7/202217/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
ModificadaMedia (4.3)0.54%—Technitium DNS Server28/3/202217/6/2026
A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific malicious users to inject `NS` records of any domain (even TLDs) into the cache and conduct a DNS cache poisoning attack.
ModificadaAlta (7.5)1.5%—Trust-dns-server Project Trust-dns-server31/12/202017/6/2026
An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption.
ModificadaAlta (7.8)0.33%—Dual Dhcp DNS Server Project Dual Dhcp DNS Server28/10/202017/6/2026
An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the DualServer.exe binary.
ModificadaAlta (7.8)0.32%—Home DNS Server Project Home DNS Server28/10/202017/6/2026
An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the HomeDNSServer.exe binary.
ModificadaAlta (7.5)6.4%—ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+321/8/202017/6/2026
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with…
ModificadaMedia (6.5)5.6%—ISC BindFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+421/8/202017/6/2026
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an…
ModificadaAlta (7.5)3.0%—ISC BindOpensuse LeapCanonical Ubuntu LinuxSynology DNS Server+121/8/202017/6/2026
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
ModificadaMedia (6.5)2.0%—Synology DNS Server24/8/201717/6/2026
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.
ModificadaAlta (7.5)6.5%—Achal Dhir Dual Dhcp DNS Server19/1/200616/6/2026
Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field.
ModificadaMedia (5)2.8%—DelegateDnrdDON Moore MydnsMaradns+1131/12/200416/6/2026
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by…