431 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-7379
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-401 1 PoC

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-7375
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6521
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6526
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

CVE-2026-7378
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6528
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

CVE-2026-3563
PowerShell Universal General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1289 1 PoC

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.

CVE-2026-6529
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6869
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1325 1 PoC

WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6530
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-7376
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-34933
avahi General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-617 1 PoC

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.

CVE-2026-6519
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6844
Red Hat Enterprise Linux 10 General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-400 1 PoC

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.

CVE-2026-4274
Mattermost General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared channel via sending crafted membership sync messages that trigger team membership assignment. Mattermost Advisory ID: MMSA-2026-00574

CVE-2026-0972
GoAnywhere MFT General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-74 1 PoC

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.

CVE-2026-0901
Chrome General
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

CVE-2026-0999
Mattermost General
5.4
MEDIUM
EPSS
0.1%
2026 CWE-303 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548

CVE-2026-26269
vim General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-121 1 PoC

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteration into a 64-byte stack buffer (keybuf) with no bounds check. A malicious NetBeans server can overflow keybuf with a single specialKeys command. The issue has been fixed as of Vim patch v9.1.2148.

CVE-2026-4430
LibreOffice General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-787 1 PoC

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.