Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
4419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.55% | — | Canonical Landscape | 6/6/2023 | 17/6/2026 | Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator. | |
| Modificada | Media (4.7) | 0.28% | — | Canonical Ubuntu Linux | 31/5/2023 | 17/6/2026 | Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock). | |
| Modificada | Media (6.5) | 0.19% | — | Canon IJ Network Tool | 17/5/2023 | 17/6/2026 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software. | |
| Modificada | Media (6.5) | 0.28% | — | Canon IJ Network Tool | 17/5/2023 | 17/6/2026 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software. | |
| Modificada | Media (5.3) | 0.54% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Arbitrary Files can be installed in the Setting Data Import function of Office / Small Office Multifunction Printers and Laser Printers(*). *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C… | |
| Modificada | Media (5.3) | 0.57% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan.… | |
| Modificada | Alta (7.5) | 0.61% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Crítica (9.8) | 1.2% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C… | |
| Modificada | Crítica (9.8) | 1.2% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in mDNS NSEC record registering process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Media (5.5) | 0.26% | — | Canonical Cloud-initCanonical Ubuntu LinuxFedoraproject Fedora | 26/4/2023 | 17/6/2026 | Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege. | |
| Modificada | Media (5.5) | 0.24% | — | Canonical Cloud-initCanonical Ubuntu Linux | 19/4/2023 | 17/6/2026 | Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords. | |
| Modificada | Media (5.5) | 0.22% | — | Canonical Cloud-init | 19/4/2023 | 17/6/2026 | When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user. | |
| Modificada | Alta (7.8) | 0.87% | 💥 PoC | Canonical ApportCanonical Ubuntu Linux | 13/4/2023 | 17/6/2026 | A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is… | |
| Modificada | Media (5.5) | 0.20% | — | Canonical Ubuntu LinuxDebian Linux | 7/4/2023 | 17/6/2026 | It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack. | |
| Modificada | Media (6.1) | 0.38% | — | Akbim Panon | 3/4/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Panon allows Reflected XSS. This issue affects Panon: before 1.0.2. | |
| Modificada | Crítica (9.8) | 0.70% | — | Akbim Panon | 3/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection. This issue affects Panon: before 1.0.2. | |
| Modificada | Alta (8.8) | 0.83% | — | Canon Mf644cdw Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.03 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BJNP service. The issue results from the lack of proper validation of… | |
| Modificada | Alta (8.8) | 1.1% | — | Canon D1620 FirmwareCanon D1650 FirmwareCanon D1520 FirmwareCanon D1550 Firmware+72 | 28/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Canon D1620 FirmwareCanon D1650 FirmwareCanon D1520 FirmwareCanon D1550 Firmware+72 | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SLP protocol. The issue results from the lack of proper… | |
| Modificada | Alta (8.8) | 1.2% | — | Canon D1620 FirmwareCanon D1650 FirmwareCanon D1520 FirmwareCanon D1550 Firmware+72 | 28/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CADM service. The issue results from the lack of proper validation of… | |
| Modificada | Alta (7.8) | 1.9% | 💥 PoC | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+9 | 27/3/2023 | 17/6/2026 | A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution. |