Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.0% | — | Pypa PIPOpensuse LeapDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+1 | 4/9/2020 | 17/6/2026 | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py. | |
| Modificada | Alta (7.5) | 3.7% | — | GnutlsFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux | 4/9/2020 | 17/6/2026 | An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls_deinit function is… | |
| Modificada | Media (6.5) | 3.0% | — | Xmlsoft Libxml2Debian LinuxFedoraproject FedoraOpensuse Leap+14 | 4/9/2020 | 17/6/2026 | GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. | |
| Modificada | Baja (3.3) | 1.5% | — | KDE ARKCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 2/9/2020 | 17/6/2026 | In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. | |
| Modificada | Media (6.1) | 3.6% | — | Golang GOFedoraproject FedoraOpensuse LeapOracle Communications Cloud Native Core Policy | 2/9/2020 | 17/6/2026 | Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header. | |
| Modificada | Media (6.5) | 4.1% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 2/9/2020 | 17/6/2026 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any… | |
| Modificada | Media (6.5) | 2.4% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 2/9/2020 | 17/6/2026 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the proxy cache and any… | |
| Modificada | Alta (7.8) | 0.41% | — | Opensuse Openldap2 | 1/9/2020 | 17/6/2026 | A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux… | |
| Modificada | Media (5.4) | 0.61% | — | Opensuse Open Build Service | 1/9/2020 | 17/6/2026 | A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build… | |
| Modificada | Media (5) | 5.4% | 💥 PoC | QemuRedhat OpenstackRedhat Enterprise LinuxFedoraproject Fedora+3 | 31/8/2020 | 17/6/2026 | An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU… | |
| Modificada | Alta (7.5) | 4.0% | — | Flask-cors Project Flask-corsDebian LinuxOpensuse Backports SLEOpensuse Leap | 31/8/2020 | 17/6/2026 | An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. | |
| Modificada | Alta (8) | 2.5% | — | Redhat LibrepoOpensuse Backports SLEOpensuse LeapFedoraproject Fedora | 30/8/2020 | 17/6/2026 | A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal.… | |
| Modificada | Alta (8.8) | 4.8% | 💥 PoC | Kleopatra Project KleopatraFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 29/8/2020 | 17/6/2026 | The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL. | |
| Modificada | Alta (8.8) | 3.1% | — | Fossil-scm FossilFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 25/8/2020 | 17/6/2026 | Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository. | |
| Modificada | Alta (7.5) | 5.0% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 24/8/2020 | 17/6/2026 | Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply()… | |
| Modificada | Alta (7.3) | 0.53% | — | PostgresqlDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 24/8/2020 | 17/6/2026 | It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions… | |
| Modificada | Alta (7.1) | 2.2% | — | PostgresqlOpensuse Leap | 24/8/2020 | 17/6/2026 | It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for… | |
| Modificada | Media (4.3) | 3.7% | — | ISC BindNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu LinuxDebian Linux+2 | 21/8/2020 | 17/6/2026 | In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these… | |
| Modificada | Alta (7.5) | 6.4% | — | ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+3 | 21/8/2020 | 17/6/2026 | In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with… | |
| Modificada | Media (6.5) | 5.6% | — | ISC BindFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+4 | 21/8/2020 | 17/6/2026 | In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an… | |
| Modificada | Alta (7.5) | 3.0% | — | ISC BindOpensuse LeapCanonical Ubuntu LinuxSynology DNS Server+1 | 21/8/2020 | 17/6/2026 | In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected. | |
| Modificada | Alta (7.5) | 3.7% | — | ISC BindOpensuse LeapNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu Linux | 21/8/2020 | 17/6/2026 | In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit. | |
| Modificada | Alta (7.8) | 1.0% | 💥 PoC | Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+6 | 19/8/2020 | 17/6/2026 | A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. | |
| Modificada | Alta (7.1) | 0.36% | — | Linux KernelCanonical Ubuntu LinuxOpensuse LeapOracle Sd-wan Edge+1 | 19/8/2020 | 17/6/2026 | In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered. | |
| Analizada | Crítica (10) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft Windows Server 1903Microsoft Windows Server 1909Microsoft Windows Server 2004Microsoft Windows Server 2008+11 | 17/8/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the… |