Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

6914 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.21%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: clk: Get runtime PM before walking tree during disable_unused Doug reported [1] the following hung task: The first thread is walking the clk tree and calling clk_pm_runtime_get() to power on devices required to read the clk hardware via struct…
AnalizadaMedia (5.5)0.28%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: comedi: vmk80xx: fix incomplete endpoint checking While vmk80xx does have endpoint checking implemented, some things can fall through the cracks. Depending on the hardware model, URBs can have either bulk or interrupt type, and current version of…
AnalizadaAlta (7.8)0.33%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: serial: mxs-auart: add spinlock around changing cts state The uart_handle_cts_change() function in serial_core expects the caller to hold uport->lock. For example, I have seen the below kernel splat, when the Bluetooth driver is loaded on an i.MX28…
ModificadaMedia (5.5)0.29%—Linux KernelDebian LinuxFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: speakup: Avoid crash on very long word In case a console is set up really large and contains a really long word (> 256 characters), we have to stop before the length of the word buffer.
ModificadaAlta (7.8)0.28%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: init/main.c: Fix potential static_command_line memory overflow We allocate memory of size 'xlen + strlen(boot_command_line) + 1' for static_command_line, but the strings copied into static_command_line are extra_command_line and command_line, rather…
ModificadaMedia (5.5)0.18%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled When I did hard offline test with hugetlb pages, below deadlock occurs: ====================================================== WARNING: possible circular locking dependency…
ModificadaMedia (5.5)0.23%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix memory leak in create_process failure Fix memory leak due to a leaked mmget reference on an error handling code path that is triggered when attempting to create KFD processes while a GPU reset is in progress.
AplazadaAlta (8.8)23%—R Project RAI29/4/202417/6/2026
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
AnalizadaMedia (4.3)0.41%—Crelly Slider Project Crelly Slider29/4/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly Slider: from n/a through 1.4.5.
ModificadaCrítica (9.4)33%💥 PoCPHPFedoraproject Fedora29/4/202417/6/2026
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
ModificadaAlta (8.8)0.23%—MF GIG Calendar Project MF GIG Calendar26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1.
ModificadaMedia (6.5)1.1%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202417/6/2026
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaCrítica (9.8)1.4%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202417/6/2026
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202410/9/2026
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaCrítica (9.8)0.77%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. This occurs when `WCHAR` string is read with twice the size it has and converted to `UTF-8`, `base64` decoded. The string is only used to compare against the redirection…
ModificadaAlta (7.5)1.2%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
ModificadaAlta (7.5)1.2%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
ModificadaCrítica (9.8)1.2%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read if `((nWidth == 0) and (nHeight == 0))`. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
ModificadaCrítica (9.8)1.4%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
AnalizadaMedia (6.5)1.5%—Matrix SynapseFedoraproject Fedora23/4/202417/6/2026
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the…
ModificadaMedia (5.5)0.32%—Linux KernelDebian LinuxFedoraproject Fedora23/4/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.
ModificadaCrítica (9.8)1.9%—FreerdpFedoraproject Fedora22/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g.…
ModificadaCrítica (9.8)3.7%💥 PoCFreerdpFedoraproject Fedora22/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.
ModificadaCrítica (9.8)1.9%—FreerdpFedoraproject Fedora22/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support).
AnalizadaCrítica (9.8)1.9%—FreerdpFedoraproject Fedora22/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gfx` (on by default, set `/bpp` or `/rfx` options instead.