Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.7% | — | SambaDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+13 | 18/2/2022 | 17/6/2026 | A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total… | |
| Modificada | Alta (8.1) | 1.6% | — | SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+21 | 18/2/2022 | 17/6/2026 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. | |
| Modificada | Media (5.9) | 1.8% | — | SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+20 | 18/2/2022 | 17/6/2026 | A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. | |
| Modificada | Alta (7.8) | 0.44% | — | Canonical SnapdCanonical Ubuntu LinuxFedoraproject Fedora | 17/2/2022 | 17/6/2026 | snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04,… | |
| Modificada | Alta (7.8) | 0.95% | 💥 PoC | Canonical SnapdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 17/2/2022 | 17/6/2026 | A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain… | |
| Modificada | Alta (8.8) | 0.35% | — | Canonical SnapdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 17/2/2022 | 17/6/2026 | snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1 | |
| Modificada | Media (5.5) | 0.26% | — | Canonical SnapdCanonical Ubuntu Linux | 17/2/2022 | 17/6/2026 | snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1 | |
| Analizada | Alta (7.8) | 24% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+2 | 16/2/2022 | 17/6/2026 | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to… | |
| Modificada | Media (4.8) | 0.84% | — | Canon 2204fCanon 2204nCanon 2206ifCanon Lbp113w+30 | 8/2/2022 | 17/6/2026 | Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW,… | |
| Modificada | Crítica (9.1) | 2.8% | — | StrongswanDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+1 | 31/1/2022 | 17/6/2026 | In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication. | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… | |
| Modificada | Alta (7.8) | 0.49% | — | Advanced Intrusion Detection Environment Project Advanced Intrusion Detection EnvironmentRedhat Ovirt-nodeRedhat Virtualization HostRedhat Enterprise Linux+3 | 20/1/2022 | 17/6/2026 | AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 3.1% | — | ClamavDebian LinuxCanonical Ubuntu Linux | 14/1/2022 | 17/6/2026 | A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an… | |
| Modificada | Crítica (9.8) | 1.2% | — | Anonaddy | 15/12/2021 | 9/7/2026 | A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php. | |
| Modificada | Alta (7.3) | 2.5% | — | Djangoproject DjangoRedhat SatelliteDebian LinuxCanonical Ubuntu Linux+1 | 8/12/2021 | 17/6/2026 | In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | Canon Lbp223dw Firmware | 6/12/2021 | 17/6/2026 | In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability. | |
| Modificada | Alta (7.8) | 0.37% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 17/11/2021 | 17/6/2026 | Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions… | |
| Modificada | Alta (7.8) | 0.25% | — | Canonical Multipass | 1/10/2021 | 17/6/2026 | The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner. | |
| Modificada | Media (5.5) | 0.46% | — | Canonical Apport | 1/10/2021 | 17/6/2026 | — | |
| Modificada | Media (5.5) | 0.46% | — | Canonical Apport | 1/10/2021 | 17/6/2026 | — | |
| Modificada | Alta (8.8) | 0.25% | — | Canonical Multipass | 1/10/2021 | 17/6/2026 | The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Canon | 29/8/2021 | 17/6/2026 | Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an… | |
| Modificada | Media (6.1) | 0.66% | — | Canon OCE Print Exec Workgroup | 23/8/2021 | 17/6/2026 | Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter. | |
| Modificada | Media (5.3) | 0.81% | — | Canon OCE Print Exec Workgroup | 23/8/2021 | 17/6/2026 | Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection. | |
| Modificada | Alta (7.8) | 0.98% | 💥 Exploit | Canon Pixma Tr150 Firmware | 11/8/2021 | 17/6/2026 | The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver… |