Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.58%—MoodleFedoraproject Fedora19/2/202417/6/2026
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
AnalizadaMedia (5.3)0.53%—MoodleFedoraproject Fedora19/2/202417/6/2026
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
AnalizadaMedia (5.3)0.59%—MoodleFedoraproject Fedora19/2/202417/6/2026
The URL parameters accepted by forum search were not limited to the allowed parameters.
AnalizadaAlta (7.5)0.94%—MoodleFedoraproject Fedora19/2/202417/6/2026
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
ModificadaCrítica (9.8)4.8%—Postgresql Jdbc DriverFedoraproject Fedora19/2/202417/6/2026
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the…
ModificadaAlta (8.8)1.8%—Videolan Dav1dApple SafariApple IpadosApple Iphone OS+319/2/202417/6/2026
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
ModificadaAlta (7.3)0.32%—Fedoraproject UnboundRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+1515/2/20246/8/2026
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to…
AnalizadaAlta (7.5)74%💥 PoCNetapp HCI Baseboard Management ControllerNetapp Active IQ Unified ManagerNetapp Bootstrap OSPowerdns Recursor+414/2/202417/6/2026
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an…
ModificadaAlta (7.5)100%💥 PoCRedhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+914/2/202417/6/2026
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the…
ModificadaAlta (7.5)1.3%—MOD Auth OpenidcDebian LinuxFedoraproject Fedora13/2/202417/6/2026
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of…
ModificadaAlta (7.5)1.2%—Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind13/2/202417/6/2026
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and…
ModificadaAlta (7.5)1.2%—Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind13/2/202417/6/2026
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when:
ModificadaAlta (7.5)1.3%—Netapp OntapFedoraproject FedoraISC Bind13/2/202417/6/2026
The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative…
ModificadaBaja (3.4)0.42%—Opensc Project OpenscFedoraproject FedoraRedhat Enterprise Linux12/2/202417/6/2026
The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present…
ModificadaMedia (5.3)0.88%—Latchset JwcryptoFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux FOR ARM 64+212/2/202417/6/2026
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.
ModificadaMedia (5.5)0.31%—Redhat 389 Directory ServerRedhat Directory ServerFedoraproject FedoraRedhat Enterprise Linux+912/2/202417/6/2026
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
ModificadaMedia (5.5)0.25%—Linux KernelFedoraproject Fedora12/2/202417/6/2026
dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and crash, because of a missing check for struct dm_ioctl.target_count.
ModificadaMedia (5.5)0.27%—Debian LinuxFedoraproject FedoraRedhat Enterprise LinuxLinux Kernel11/2/202417/6/2026
A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a…
ModificadaAlta (7.8)1.2%—X.org X ServerX.org XwaylandFedoraproject FedoraRedhat Enterprise Linux+49/2/202417/6/2026
An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution…
ModificadaMedia (4.7)0.23%—Linux KernelFedoraproject Fedora8/2/202417/6/2026
A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time with a fail in the mas_prev_slot function. This issue could allow a local user to crash the system.
ModificadaAlta (7.5)33%—Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora7/2/202417/6/2026
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker…
ModificadaCrítica (9.8)1.1%—Google ChromeFedoraproject Fedora7/2/202417/6/2026
Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.8)22%—Google ChromeFedoraproject Fedora7/2/202417/6/2026
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaBaja (3.3)0.27%—GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora6/2/202417/6/2026
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may…
ModificadaMedia (5.5)0.30%—Redhat AnsibleRedhat Enterprise LinuxRedhat Ansible Automation PlatformRedhat Ansible Developer+26/2/202417/6/2026
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.