832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-5406
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-674 2 PoCs

FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-22795
OpenSSL General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-754 1 PoC

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses betwee

CVE-2026-7379
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-401 1 PoC

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-28288
dify Web ⚡ nuclei
5.5
MEDIUM
EPSS
0.5%
2026 CWE-204 0 PoCs

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

CVE-2026-25541
bytes Web
5.5
MEDIUM
EPSS
0.0%
2026 CWE-680 1 PoC

Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. When new_cap + offset overflows usize in release builds, this condition may incorrectly pass, causing self.cap to be set to a value that exceeds the actual allocated capacity. Subsequent APIs such as spare_capacity_mut() then trust this corrupted cap value and may create out-of-bounds slices, leading to UB. This behavior

CVE-2026-3777
Foxit PDF Editor Web
5.5
MEDIUM
EPSS
0.0%
2026 CWE-416 1 PoC

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.

CVE-2026-7375
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-34933
avahi General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-617 1 PoC

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.

CVE-2026-7378
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6521
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6528
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

CVE-2026-3563
PowerShell Universal General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1289 1 PoC

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.

CVE-2026-6526
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

CVE-2026-6529
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6524
Wireshark Database
5.5
MEDIUM
EPSS
0.0%
2026 CWE-824 1 PoC

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6519
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6869
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1325 1 PoC

WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-7376
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6522
Wireshark Networking
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 1 PoC

RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6844
Red Hat Enterprise Linux 10 General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-400 1 PoC

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.