Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

259 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.45%—Linux KernelOpensuse LeapDebian LinuxNetapp Active IQ Unified Manager+185/5/202017/6/2026
An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea.
ModificadaAlta (7)0.53%—GNU GlibcCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp HCI Management Node+430/4/202017/6/2026
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that,…
ModificadaMedia (6.1)99%💥 ExploitJqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
AnalizadaMedia (6.1)85%⚠ Explotación activa💥 ExploitJqueryDebian LinuxFedoraproject FedoraDrupal+4829/4/202017/6/2026
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaAlta (7)0.40%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1929/4/202017/6/2026
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur.
ModificadaAlta (7.5)4.4%—OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1428/4/202017/6/2026
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
ModificadaMedia (5.5)0.45%—Canonical Ubuntu LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management NodeNetapp Steelstore Cloud Integrated Storage+2810/4/202017/6/2026
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this…
ModificadaMedia (5.5)0.76%—GNU GlibcFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+74/3/202017/6/2026
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to…
ModificadaMedia (5.5)0.52%—Linux KernelFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+525/2/202017/6/2026
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause…
ModificadaAlta (7.1)0.76%—Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+825/2/202017/6/2026
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
ModificadaMedia (5.5)0.42%—Linux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+614/2/202017/6/2026
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
ModificadaAlta (7.5)7.8%—Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+2021/1/202017/6/2026
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
AnalizadaAlta (7.8)72%⚠ Explotación activa💥 ExploitGoogle AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+7311/10/201917/6/2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing…
ModificadaAlta (7.5)3.5%—Linux KernelOpensuse LeapNetapp AFF A700s FirmwareNetapp H300s Firmware+1330/9/201917/6/2026
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
ModificadaAlta (7.8)0.87%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+3020/9/201917/6/2026
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
ModificadaAlta (8.8)0.76%—Linux KernelRedhat Virtualization HostRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2419/9/201917/6/2026
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be…
ModificadaAlta (7.8)0.62%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+3017/9/201917/6/2026
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could…
ModificadaAlta (7.5)3.9%—Linux KernelCanonical Ubuntu LinuxNetapp Data Availability ServicesNetapp HCI Management Node+1425/8/201917/6/2026
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack…
ModificadaMedia (4.6)0.60%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+319/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c driver.
ModificadaMedia (4.6)0.60%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+319/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.2.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/helper.c (motu_microbookii) driver.
ModificadaMedia (4.6)0.71%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver.
ModificadaMedia (4.6)0.76%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver.
ModificadaMedia (4.6)0.71%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver.
ModificadaMedia (4.6)0.84%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+619/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver.
ModificadaMedia (4.6)0.68%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.
Orbitaley — Vulnerabilidades