Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

368 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)7.2%—Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Virtualization+522/1/201817/6/2026
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
ModificadaAlta (7.8)0.37%—Linux KernelCanonical Ubuntu LinuxRedhat VirtualizationRedhat Enterprise Linux Desktop+212/1/201817/6/2026
In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.
ModificadaAlta (7)0.48%—Redhat Hibernate ValidatorRedhat SatelliteRedhat Satellite CapsuleRedhat Jboss Enterprise Application Platform+210/1/201817/6/2026
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access…
ModificadaAlta (7.4)1.2%—Redhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+611/12/201717/6/2026
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
ModificadaAlta (7.5)4.2%—Linux KernelDebian LinuxRedhat Virtualization HostRedhat Enterprise Linux Desktop+57/12/201717/6/2026
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the…
ModificadaMedia (6.2)4.9%—Apache StrutsNetapp Oncommand BalanceOracle Agile PLM FrameworkOracle Enterprise Manager FOR Virtualization+81/12/201717/6/2026
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
ModificadaCrítica (9.8)86%💥 ExploitRedhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+119/11/201717/6/2026
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat…
ModificadaCrítica (9.1)3.4%—Redhat Enterprise Virtualization Manager25/9/201717/6/2026
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
ModificadaMedia (5.9)1.9%—Redhat Enterprise Virtualization Manager24/8/201717/6/2026
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
ModificadaMedia (5.5)0.36%—Redhat Enterprise Virtualization22/8/201717/6/2026
oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
ModificadaAlta (7.5)4.0%—QemuDebian LinuxRedhat VirtualizationRedhat Openstack+62/8/201717/6/2026
qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.
ModificadaAlta (7.8)0.63%—QemuCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+725/7/201717/6/2026
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
ModificadaAlta (7)0.50%—Redhat Enterprise Virtualization ServerRedhat OpenshiftRedhat Enterprise LinuxDebian Linux+219/6/201717/6/2026
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1…
ModificadaCrítica (9.8)2.9%—OpenvswitchDebian LinuxRedhat OpenstackRedhat Virtualization+123/5/201717/6/2026
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
ModificadaMedia (6.8)0.52%—Redhat Enterprise Virtualization20/4/201717/6/2026
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries.
ModificadaMedia (5.5)0.46%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization27/3/201717/6/2026
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.
ModificadaMedia (6.5)0.41%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization23/12/201617/6/2026
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.
ModificadaMedia (6.5)0.38%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization23/12/201617/6/2026
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
ModificadaMedia (6.5)0.43%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization23/12/201617/6/2026
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
ModificadaMedia (5.5)0.24%—Redhat Enterprise Virtualization14/12/201617/6/2026
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
ModificadaMedia (6)0.42%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization10/12/201617/6/2026
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.
ModificadaMedia (6)0.36%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization10/12/201617/6/2026
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
ModificadaMedia (4.4)0.40%—QemuDebian LinuxRedhat VirtualizationRedhat Openstack10/12/201617/6/2026
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
ModificadaMedia (6)0.39%—QemuRedhat VirtualizationDebian Linux10/12/201617/6/2026
The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP header length.
ModificadaMedia (6)0.41%—QemuDebian LinuxOpensuse LeapRedhat Openstack+14/11/201617/6/2026
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.