Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
3733 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Redhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUS+13 | 7/2/2024 | 17/6/2026 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a denial of service. | |
| Modificada | Baja (3.3) | 0.27% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 6/2/2024 | 17/6/2026 | A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may… | |
| Modificada | Media (5.5) | 0.30% | — | Redhat AnsibleRedhat Enterprise LinuxRedhat Ansible Automation PlatformRedhat Ansible Developer+2 | 6/2/2024 | 17/6/2026 | An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+1 | 5/2/2024 | 17/6/2026 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Analizada | Alta (7.5) | 1.1% | — | Redhat Enterprise LinuxRedhat Update InfrastructureM2crypto Project M2crypto | 5/2/2024 | 16/9/2026 | A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Modificada | Media (5.3) | 0.90% | — | GNU CpioRedhat Enterprise Linux | 5/2/2024 | 17/6/2026 | A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in… | |
| Modificada | Media (6.5) | 0.97% | — | Linux KernelRedhat Enterprise Linux | 4/2/2024 | 17/6/2026 | A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key. | |
| Modificada | Media (5.9) | 1.2% | — | Opensc Project OpenscRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+7 | 31/1/2024 | 17/6/2026 | A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. | |
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa💥 PoC | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Modificada | Media (5.9) | 0.88% | — | Opencryptoki Project OpencryptokiRedhat Enterprise Linux | 31/1/2024 | 17/6/2026 | A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key. | |
| Modificada | Media (6.5) | 0.62% | — | Linux KernelRedhat Enterprise Linux | 30/1/2024 | 17/6/2026 | A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is… | |
| Modificada | Media (5.1) | 0.40% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase. | |
| Modificada | Media (5.5) | 0.40% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase. | |
| Modificada | Media (5.5) | 0.41% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.44% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain… | |
| Modificada | Alta (7.8) | 0.30% | — | Linux KernelRedhat Enterprise Linux | 28/1/2024 | 17/6/2026 | A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.5) | 2.2% | 💥 PoC | LibtiffRedhat Enterprise Linux | 25/1/2024 | 17/6/2026 | A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service. | |
| Modificada | Alta (7.5) | 1.8% | — | LibtiffRedhat Enterprise Linux | 25/1/2024 | 2/10/2026 | An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB. | |
| Modificada | Alta (8.3) | 5.4% | — | Redhat ShimRedhat Enterprise Linux | 25/1/2024 | 26/6/2026 | A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This… | |
| Modificada | Alta (7.1) | 0.22% | — | Linux KernelRedhat Enterprise Linux | 22/1/2024 | 10/8/2026 | A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, leading to a use-after-free. | |
| Modificada | Alta (7) | 0.22% | — | Linux KernelRedhat Enterprise Linux | 21/1/2024 | 6/8/2026 | A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on. | |
| Modificada | Media (6.6) | 0.24% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 18/1/2024 | 17/6/2026 | A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of u32, so each element only has space for 4 bytes. That means every… | |
| Modificada | Alta (7.8) | 0.36% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context. | |
| Modificada | Media (5.5) | 0.32% | — | TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+8 | 18/1/2024 | 17/6/2026 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX… | |
| Modificada | Crítica (9.8) | 2.1% | — | X.org X ServerX.org XwaylandFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 18/1/2024 | 17/6/2026 | A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow… |