Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)9.4%—Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Supplementary+514/4/201517/6/2026
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
AnalizadaCrítica (9.8)74%⚠ Explotación activa💥 ExploitAdobe Flash PlayerNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Workstation ExtensionOpensuse Evergreen+714/4/201517/6/2026
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than…
ModificadaMedia (4.3)1.1%—Maroyaka Relay Novel Project Maroyaka Relay Novel5/3/201517/6/2026
Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Relay Novel allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)88%💥 ExploitRedhat Enterprise LinuxSambaNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+224/2/201517/6/2026
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the…
ModificadaAlta (9.3)4.0%—Oracle JDKOracle JRENovell Suse Linux Enterprise Desktop21/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
ModificadaMedia (6.9)0.39%—Oracle JDKOracle JRENovell Suse Linux Enterprise Desktop21/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process.
ModificadaAlta (7.2)1.5%—Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+421/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.
ModificadaMedia (5)5.0%—Oracle JDKOracle JREOracle JrockitCanonical Ubuntu Linux+521/1/201517/6/2026
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
ModificadaAlta (10)6.9%—Oracle JDKOracle JRECanonical Ubuntu LinuxDebian Linux+421/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.
ModificadaMedia (5.8)3.9%—Oracle JDKOracle JRENovell Suse Linux Enterprise Desktop21/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment.
ModificadaMedia (6.9)0.44%—Novell Suse Linux Enterprise DesktopOracle JDKOracle JRE21/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
ModificadaMedia (5)4.2%—Canonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+221/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
ModificadaAlta (9.3)5.9%—Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise ServerOpensuse+321/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
ModificadaMedia (5.4)0.45%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraNovell Suse Linux Enterprise Desktop+621/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot.
ModificadaAlta (10)6.9%—Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+421/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
ModificadaMedia (4)2.0%—Novell Edirectory19/12/201417/6/2026
nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote authenticated users to obtain sensitive information from process memory via a direct request.
ModificadaMedia (4.3)2.0%—Novell Edirectory19/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML via the rdn parameter.
ModificadaMedia (5.5)0.74%—Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+710/11/201417/6/2026
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
ModificadaMedia (5.5)0.52%—Linux KernelNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Evergreen+610/11/201417/6/2026
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm…
ModificadaAlta (7.5)8.6%—Linux KernelRedhat Enterprise MRGCanonical Ubuntu LinuxDebian Linux+810/11/201417/6/2026
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.
ModificadaBaja (3.4)100%💥 PoCRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+1615/10/201417/6/2026
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
ModificadaMedia (5.5)0.67%—Novell Suse Linux Enterprise ServerLinux KernelCanonical Ubuntu Linux13/10/201417/6/2026
The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.
ModificadaMedia (4.9)0.53%—Linux KernelNovell Suse Linux Enterprise Server28/9/201416/6/2026
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7025/9/201417/6/2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7024/9/201417/6/2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the…
Orbitaley — Vulnerabilidades