Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.97%—Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+27/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
ModificadaMedia (4.4)0.41%—Linux KernelCanonical Ubuntu Linux10/2/202117/6/2026
Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by…
ModificadaAlta (7.8)0.42%—Linux KernelCanonical Ubuntu LinuxDebian Linux14/1/202117/6/2026
Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196.
ModificadaMedia (5.5)0.19%—Canonical Remote-login-service13/1/202116/6/2026
In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-0ubuntu3 and prior versions.
AnalizadaMedia (5.5)1.5%—Gnome Gdk-pixbufCanonical Ubuntu LinuxFedoraproject Fedora26/12/202017/6/2026
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the…
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux9/12/202017/6/2026
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
ModificadaBaja (3.8)0.34%—Canonical Ubuntu Linux9/12/202017/6/2026
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
ModificadaMedia (6.8)0.70%—Canonical SnapcraftCanonical Ubuntu Linux4/12/202017/6/2026
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and…
ModificadaMedia (4.7)0.32%—Canonical Ubuntu Linux4/12/202017/6/2026
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to…
ModificadaAlta (7.4)0.61%—Canonical Software-properties2/12/202016/6/2026
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only checked certificates under python3 if a valid certificate bundle was provided. Fixed in…
ModificadaAlta (7.5)1.1%—Canon Mf237w FirmwareCanon Mf113w FirmwareCanon Mf212w FirmwareCanon Mf216n Firmware+2430/11/202017/6/2026
An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated network attacker, may expose Sensitive Information.
ModificadaMedia (4.7)0.40%—Linux KernelCanonical Ubuntu Linux28/11/202017/6/2026
An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.
ModificadaMedia (5.7)0.56%—Intel Ax201 FirmwareIntel Ax200 FirmwareIntel AC 9560 FirmwareIntel AC 9462 Firmware+1123/11/202017/6/2026
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaCrítica (9.8)1.1%—Canon OCE Colorwave 3500 Firmware16/11/202017/6/2026
The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.
ModificadaAlta (7.8)0.34%—Packagekit Project PackagekitCanonical Ubuntu Linux7/11/202017/6/2026
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
ModificadaBaja (3.3)0.47%—Packagekit Project PackagekitCanonical Ubuntu Linux7/11/202017/6/2026
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
ModificadaAlta (7.8)0.40%—Canonical Ubuntu Linux6/11/202017/6/2026
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
ModificadaMedia (4.3)1.1%—WordpressDebian LinuxCanonical Ubuntu Linux2/11/202017/6/2026
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
ModificadaCrítica (9.1)4.1%—WordpressDebian LinuxCanonical Ubuntu Linux2/11/202017/6/2026
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
ModificadaMedia (4.9)2.3%—Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+221/10/202017/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.1)2.3%—Linuxfoundation ContainerdCanonical Ubuntu LinuxDebian Linux16/10/202017/6/2026
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the…
ModificadaAlta (7.5)2.4%—Linux KernelDebian LinuxNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+313/10/202017/6/2026
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this…
ModificadaMedia (6.6)2.7%—Spice Project SpiceRedhat OpenstackCanonical Ubuntu LinuxDebian Linux+67/10/202017/6/2026
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when…
ModificadaMedia (5.5)0.39%—Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+16/10/202017/6/2026
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block…
ModificadaMedia (5.3)5.0%—PHPFedoraproject FedoraDebian LinuxOpensuse Leap+32/10/202017/6/2026
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge…