Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3733 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.31% | — | Linux KernelRedhat Enterprise Linux | 17/1/2024 | 6/8/2026 | An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelRedhat Enterprise Linux | 17/1/2024 | 17/6/2026 | A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system. | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelRedhat Enterprise Linux | 17/1/2024 | 21/7/2026 | A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system. | |
| Modificada | Crítica (9.8) | 1.6% | — | Rpm-software-management MockFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in… | |
| Modificada | Media (5.5) | 0.38% | — | SqliteRedhat Enterprise LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | GnutlsFedoraproject FedoraRedhat Enterprise Linux | 16/1/2024 | 17/6/2026 | A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading… | |
| Modificada | Alta (7.8) | 0.25% | — | Linux KernelRedhat Enterprise Linux | 15/1/2024 | 17/6/2026 | A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated delayed work to complete. However, wb_inode_writeback_end() may schedule bandwidth estimation work after this has completed, which can result in the timer attempting… | |
| Modificada | Media (6.8) | 0.54% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 15/1/2024 | 17/6/2026 | An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a… | |
| Modificada | Media (5.5) | 0.26% | — | Linux KernelRedhat Enterprise Linux | 15/1/2024 | 17/6/2026 | A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return. | |
| Modificada | Media (5.5) | 0.29% | — | Relax-and-recoverSuse Linux EnterpriseRedhat Enterprise LinuxFedoraproject Fedora | 12/1/2024 | 17/6/2026 | Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root. | |
| Analizada | Media (6.5) | 1.3% | — | QemuRedhat Enterprise Linux | 12/1/2024 | 17/6/2026 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious… | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 12/1/2024 | 21/7/2026 | A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency… | |
| Modificada | Media (6.5) | 0.57% | — | FreeipaFedoraproject FedoraRedhat Codeready Linux BuilderRedhat Enterprise Linux+17 | 10/1/2024 | 17/6/2026 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration… | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux | 8/1/2024 | 17/6/2026 | It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code. | |
| Modificada | Baja (3.3) | 0.23% | — | Packagekit Project PackagekitRedhat Enterprise LinuxFedoraproject Fedora | 3/1/2024 | 17/6/2026 | A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored… | |
| Modificada | Media (4.8) | 0.45% | — | LibsshFedoraproject FedoraRedhat Enterprise Linux | 3/1/2024 | 17/6/2026 | A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter. | |
| Modificada | Media (4.4) | 0.30% | — | Linux KernelRedhat Enterprise Linux | 2/1/2024 | 17/6/2026 | A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow. | |
| Analizada | Media (6.7) | 0.84% | — | Redhat Codeready Linux Builder FOR EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUSRedhat Codeready Linux Builder FOR Power Little Endian EUSRedhat Enterprise Linux+18 | 2/1/2024 | 17/6/2026 | A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with… | |
| Modificada | Media (5.3) | 0.33% | — | QemuRedhat Enterprise LinuxFedoraproject Fedora | 2/1/2024 | 17/6/2026 | A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables… | |
| Modificada | Media (5.5) | 0.26% | — | Shadow-maint Shadow-utilsRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR IBM Z Systems+5 | 27/12/2023 | 17/6/2026 | A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory. | |
| Modificada | Alta (7) | 0.66% | — | Openbsd OpensshFedoraproject FedoraRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the… | |
| Modificada | Media (5.3) | 1.1% | — | EximFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 24/12/2023 | 17/6/2026 | Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other… | |
| Modificada | Media (5.3) | 1.1% | — | SendmailFreebsdRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular… | |
| Modificada | Media (5.3) | 2.6% | 💥 PoC | PostfixFedoraproject FedoraRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed… | |
| Modificada | Alta (7) | 0.73% | 💥 PoC | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 21/12/2023 | 6/8/2026 | A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This… |