Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.4% | — | UI Edgeswitch FirmwareOpensuse Backports SLEOpensuse Leap | 17/8/2020 | 17/6/2026 | A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges. | |
| Modificada | Media (6.5) | 2.6% | — | WiresharkFedoraproject FedoraOpensuse LeapOracle ZFS Storage Appliance KIT | 13/8/2020 | 17/6/2026 | In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression. | |
| Modificada | Media (4.3) | 0.55% | — | Gnome-shellCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 11/8/2020 | 17/6/2026 | An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment… | |
| Modificada | Crítica (9.8) | 4.1% | — | Firejail Project FirejailDebian LinuxFedoraproject FedoraOpensuse Leap | 11/8/2020 | 17/6/2026 | Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection. | |
| Modificada | Alta (7.8) | 1.5% | — | Firejail Project FirejailDebian LinuxFedoraproject FedoraOpensuse Leap | 11/8/2020 | 17/6/2026 | Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection. | |
| Modificada | Baja (3.8) | 0.38% | — | QemuDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 11/8/2020 | 17/6/2026 | In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in… | |
| Modificada | Alta (8.8) | 2.4% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdOpensuse Leap+1 | 10/8/2020 | 17/6/2026 | Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox… | |
| Modificada | Alta (8.8) | 1.5% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdOpensuse Leap+1 | 10/8/2020 | 17/6/2026 | JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1. | |
| Modificada | Media (6.5) | 1.5% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdOpensuse Leap+1 | 10/8/2020 | 17/6/2026 | A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1. | |
| Modificada | Alta (7.5) | 89% | — | Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+21 | 7/8/2020 | 17/6/2026 | Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers. | |
| Analizada | Alta (7.5) | 56% | — | Apache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxOpensuse Leap+9 | 7/8/2020 | 17/6/2026 | Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxDebian Linux+9 | 7/8/2020 | 17/6/2026 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | |
| Modificada | Alta (7.8) | 0.36% | — | Opensuse Backports SLEOpensuse TumbleweedOpensuse Leap | 7/8/2020 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE… | |
| Modificada | Alta (7.5) | 4.9% | — | Golang GOOpensuse LeapDebian LinuxFedoraproject Fedora | 6/8/2020 | 17/6/2026 | Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs. | |
| Modificada | Crítica (9.8) | 2.4% | — | LilypondFedoraproject FedoraDebian LinuxOpensuse Backports SLE+1 | 5/8/2020 | 17/6/2026 | scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code. | |
| Modificada | Media (6.7) | 0.46% | — | X.org Libx11Fedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap | 5/8/2020 | 17/6/2026 | An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat… | |
| Modificada | Baja (3.3) | 1.7% | — | KDE ARKDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 3/8/2020 | 17/6/2026 | In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal. | |
| Modificada | Media (6) | 0.46% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+3 | 31/7/2020 | 17/6/2026 | There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow. | |
| Modificada | Media (6) | 0.48% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+3 | 31/7/2020 | 17/6/2026 | There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file… | |
| Modificada | Baja (3.7) | 5.3% | — | Linux KernelOpensuse LeapFedoraproject FedoraDebian Linux+11 | 30/7/2020 | 17/6/2026 | The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c. | |
| Modificada | Media (6.7) | 0.48% | — | GNU Grub2Opensuse Leap | 30/7/2020 | 17/6/2026 | There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data. | |
| Modificada | Alta (8.2) | 1.7% | 💥 PoC | GNU Grub2Debian LinuxOpensuse LeapVmware Photon OS | 30/7/2020 | 17/6/2026 | A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as… | |
| Modificada | Media (6.4) | 0.43% | — | GNU Grub2Opensuse Leap | 29/7/2020 | 17/6/2026 | In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process. | |
| Modificada | Alta (7.5) | 2.1% | — | Gnome BalsaOpensuse Backports SLEOpensuse Leap | 29/7/2020 | 17/6/2026 | In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c. | |
| Modificada | Media (6.4) | 1.6% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 29/7/2020 | 17/6/2026 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of… |