Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried… | |
| Aplazada | Media (5.5) | 0.40% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 29/9/2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used.… | |
| Aplazada | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 29/9/2026 | A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The… | |
| Aplazada | Baja (2.1) | 0.13% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit… | |
| Pendiente de análisis | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could… | |
| Pendiente de análisis | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of… | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has… | |
| Pendiente de análisis | Media (5.5) | 0.31% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely.… | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Trusteddomain OpendmarcAI | 27/9/2026 | 1/10/2026 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch… | |
| Pendiente de análisis | Media (5.5) | 0.37% | — | Trusteddomain OpendmarcAI | 27/9/2026 | 28/9/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the… | |
| Analizada | Alta (7.5) | 0.73% | — | Trusteddomain Opendmarc | 26/2/2024 | 17/6/2026 | OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c. | |
| Modificada | Alta (7.5) | 2.7% | — | Trusteddomain OpendmarcFedoraproject Fedora | 10/6/2021 | 17/6/2026 | OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field. | |
| Modificada | Crítica (9.8) | 3.7% | — | Trusteddomain OpendmarcFedoraproject FedoraDebian Linux | 27/7/2020 | 17/6/2026 | OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap… | |
| Modificada | Media (5.3) | 2.2% | — | Trusteddomain OpendmarcFedoraproject Fedora | 27/4/2020 | 17/6/2026 | OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring. | |
| Modificada | Crítica (9.8) | 2.6% | — | Trusteddomain OpendmarcPypolicyd-spf Project Pypolicyd-spfFedoraproject Fedora | 27/4/2020 | 17/6/2026 | OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field. | |
| Modificada | Crítica (9.8) | 2.5% | — | Trusteddomain OpendmarcDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 17/9/2019 | 17/6/2026 | OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message. |