Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

609 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.43%—Oracle MysqlDebian LinuxRedhat OpenstackRedhat Enterprise Linux Desktop+68/8/201717/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.56 and earlier and 5.6.36 and earlier. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise…
ModificadaAlta (7.5)4.0%—QemuDebian LinuxRedhat VirtualizationRedhat Openstack+62/8/201717/6/2026
qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.
ModificadaAlta (7.8)0.63%—QemuCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+725/7/201717/6/2026
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
ModificadaAlta (7.5)9.1%—Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+1621/7/201717/6/2026
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to…
ModificadaAlta (7.5)6.1%—Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+1421/7/201717/6/2026
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
ModificadaAlta (7.5)6.5%—Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+921/7/201717/6/2026
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
ModificadaAlta (8.4)2.7%—HP Helion Openstack Glance27/6/201717/6/2026
The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
ModificadaAlta (7.8)2.7%💥 ExploitRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1619/6/201717/6/2026
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these…
ModificadaMedia (6.5)1.6%—Openstack Ironic7/6/201717/6/2026
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
ModificadaCrítica (9.8)2.9%—OpenvswitchDebian LinuxRedhat OpenstackRedhat Virtualization+123/5/201717/6/2026
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
ModificadaMedia (6.5)0.41%—QemuDebian LinuxRedhat Openstack23/5/201717/6/2026
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
ModificadaAlta (7.5)4.5%—QemuDebian LinuxRedhat Openstack23/5/201717/6/2026
Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
ModificadaBaja (3.8)0.37%—XENSuse ManagerSuse Manager ProxySuse Openstack Cloud+23/5/201717/6/2026
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
ModificadaMedia (5.4)1.5%—Redhat OpenstackOpenstack Manila21/4/201717/6/2026
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.
ModificadaAlta (7.5)2.9%—Canonical Ubuntu LinuxOpenstack Nova-lxd12/4/201717/6/2026
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
ModificadaMedia (4.8)1.1%—Openstack Horizon3/4/201717/6/2026
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
ModificadaCrítica (9.8)4.7%—SnoopyRedhat OpenstackNagios31/3/201717/6/2026
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
ModificadaCrítica (9.8)4.1%—SnoopyRedhat OpenstackDebian Linux31/3/201717/6/2026
Snoopy allows remote attackers to execute arbitrary commands.
ModificadaCrítica (9.8)4.5%—SnoopyRedhat OpenstackNagios31/3/201716/6/2026
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
ModificadaMedia (5.5)1.3%—Openstack Glance29/3/201717/6/2026
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
ModificadaMedia (5.5)0.46%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization27/3/201717/6/2026
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.
ModificadaCrítica (9.8)2.3%—Openstack Nova21/3/201717/6/2026
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.
AnalizadaMedia (5.8)2.1%—Openstack Glance21/3/201717/9/2026
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal…
ModificadaMedia (6.1)23%—Jqueryui Jquery UIOracle Application ExpressOracle Business IntelligenceOracle Hospitality Cruise Fleet Management+915/3/201717/6/2026
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
ModificadaMedia (4.3)3.5%—NTPSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+630/1/201717/6/2026
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.