Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

623 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)4.7%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1218/1/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access…
ModificadaMedia (5.3)6.9%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1218/1/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network…
ModificadaMedia (4.5)0.63%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+1118/1/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE,…
ModificadaMedia (4.8)4.2%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1218/1/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access…
ModificadaMedia (4.3)3.4%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1218/1/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via…
ModificadaMedia (6.5)4.7%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+918/1/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
ModificadaBaja (3.7)4.1%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1218/1/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network…
ModificadaAlta (7.8)2.2%—Fedoraproject FedoraGnome GcabCanonical Ubuntu LinuxDebian Linux+612/1/201817/6/2026
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
ModificadaAlta (8.8)74%💥 ExploitRuby-lang RubyDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+415/12/201717/6/2026
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is…
ModificadaAlta (7.4)1.2%—Redhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+611/12/201717/6/2026
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
ModificadaAlta (7.5)4.2%—Linux KernelDebian LinuxRedhat Virtualization HostRedhat Enterprise Linux Desktop+57/12/201717/6/2026
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the…
ModificadaMedia (5.5)0.40%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+37/12/201717/6/2026
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
ModificadaMedia (5.5)3.1%—Apache OpenofficeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+420/11/201717/6/2026
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document…
ModificadaAlta (7.5)40%💥 PoCOpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4113/11/201717/6/2026
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections…
ModificadaAlta (7.8)0.44%—SOS Project SOSCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+46/11/201717/6/2026
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
ModificadaCrítica (9.8)3.7%—Golang GOFedoraproject FedoraRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+218/10/201717/6/2026
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.
ModificadaCrítica (9.8)9.6%—Golang GOFedoraproject FedoraRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+218/10/201717/6/2026
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length."
ModificadaCrítica (9.8)16%—RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+511/10/201717/6/2026
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.
ModificadaCrítica (9.8)6.3%—MercurialDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+45/10/201717/6/2026
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
ModificadaAlta (7.5)4.8%—MercurialDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+45/10/201717/6/2026
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
ModificadaAlta (7.8)0.37%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+55/10/201717/6/2026
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock…
ModificadaAlta (8)16%💥 ExploitLinux KernelDebian LinuxNvidia Jetson TK1Nvidia Jetson TX1+612/9/201717/6/2026
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
ModificadaAlta (7.8)51%💥 ExploitGnome EvinceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+45/9/201717/6/2026
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the…
ModificadaAlta (8.1)4.8%—RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+531/8/201717/6/2026
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
ModificadaAlta (7.5)29%💥 ExploitRubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+531/8/201717/6/2026
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
Orbitaley — Vulnerabilidades