Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Baja (2.5) | 0.13% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection. | |
| Pendiente de análisis | Baja (2.9) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY… | |
| Pendiente de análisis | Baja (3.1) | 0.13% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected. | |
| En análisis | Baja (3.6) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled. | |
| En análisis | Baja (2.5) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283. | |
| En análisis | Media (6.5) | 0.19% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data. | |
| En análisis | Baja (2.5) | 0.06% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations. | |
| En análisis | Baja (3.7) | 0.18% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings. | |
| En análisis | Baja (2.2) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts. | |
| En análisis | Baja (2.2) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt. | |
| En análisis | Media (4.2) | 0.29% | — | Openbsd OpensshAI | 6/10/2026 | 7/10/2026 | In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation. | |
| Aplazada | Crítica (9.2) | 0.37% | — | Openbsd LdapdAI | 30/9/2026 | 1/10/2026 | In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier… | |
| Aplazada | Alta (8.2) | 0.44% | — | Ansible Freebsd Jail Connection PluginAI | 21/9/2026 | 24/9/2026 | Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic… | |
| Aplazada | Media (5.3) | 0.47% | — | Midnightbsd MportAI | 21/9/2026 | 25/9/2026 | mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled… | |
| Aplazada | Media (5.8) | 0.10% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot… | |
| Aplazada | Media (6) | 0.54% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file… | |
| Aplazada | Alta (8.3) | 0.54% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing… | |
| Aplazada | Media (6) | 0.55% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply… | |
| Aplazada | Alta (8.3) | 0.22% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror… | |
| Aplazada | Media (6) | 0.15% | — | Midnightbsd MportAI | 17/9/2026 | 21/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement check. When a cleartext URL was configured or returned by… | |
| Aplazada | Alta (8.3) | 0.26% | — | Midnightbsd MportAI | 17/9/2026 | 24/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed… | |
| Aplazada | Baja (2.3) | 0.16% | — | Midnightbsd MportAI | 17/9/2026 | 24/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency… | |
| Aplazada | Baja (2) | 0.11% | — | Midnightbsd MportAI | 17/9/2026 | 18/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the… | |
| Aplazada | Baja (2) | 0.16% | — | Midnightbsd MportAI | 17/9/2026 | 24/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such as -r before a package name, stale optind state and the… | |
| Aplazada | Media (5.8) | 0.10% | — | Midnightbsd MportAI | 17/9/2026 | 18/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink… |