Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 562 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.16% | — | Connorskees GrassAI | 4/7/2026 | 6/7/2026 | A vulnerability has been found in connorskees grass up to 0.13.4. The impacted element is the function grass_compiler::selector::extend/grass_compiler::evaluate::visitor. The manipulation leads to denial of service. The attack must be carried out locally. The exploit has been disclosed to the public and may be used.… | |
| Aplazada | Baja (1.9) | 0.16% | — | Connorskees GrassAI | 4/7/2026 | 6/7/2026 | A flaw has been found in connorskees grass up to 0.13.4. The affected element is the function grass_compiler::raw_to_parse_error of the component UTF-8 Character Handler. Executing a manipulation can lead to denial of service. The attack is restricted to local execution. The exploit has been published and may be used.… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | GrassmarlinAI | 28/4/2026 | 17/6/2026 | A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process. | |
| Pendiente de análisis | Alta (8.7) | 0.61% | — | Grassroots GdcmAI | 26/3/2026 | 17/6/2026 | A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill… | |
| Analizada | Crítica (9.1) | 0.34% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `null_convert` is called based of the value of the… | |
| Analizada | Crítica (9.1) | 0.32% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `grayscale_convert` is called based of the value of… | |
| Analizada | Alta (7.5) | 0.41% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Crítica (9.1) | 0.43% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An attacker can provide a malicious file to trigger this vulnerability. | |
| Aplazada | Media (6.8) | 0.15% | — | Grassroots GdcmAI | 12/12/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caused by an… | |
| Modificada | Media (6.5) | 1.1% | — | Malaterre Grassroots DicomFedoraproject Fedora | 25/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Crítica (9.8) | 1.4% | — | Malaterre Grassroots DicomFedoraproject Fedora | 25/4/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Malaterre Grassroots DicomFedoraproject Fedora | 25/4/2024 | 10/9/2026 | An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Media (5.3) | 0.76% | — | Grassroot Platform | 19/4/2021 | 17/6/2026 | Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Grassroot Platform before master deployment as of 2021-04-16 did not properly verify the signature of JSON Web Tokens when refreshing an existing JWT. This allows to forge… | |
| Modificada | Alta (8.2) | 3.6% | — | Malaterre Grassroots Dicom | 12/1/2016 | 17/6/2026 | The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the… | |
| Modificada | Crítica (10) | 16% | — | Malaterre Grassroots Dicom | 12/1/2016 | 17/6/2026 | Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image file, which triggers a buffer overflow. | |
| Modificada | Media (5.4) | 0.27% | — | Grasshopper Beta | 28/9/2014 | 17/6/2026 | The Grasshopper Beta (aka com.grasshopper.dialer) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Grassapper Slideshow 365 | 17/9/2014 | 17/6/2026 | The Slideshow 365 (aka com.Slideshow) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |