Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

3733 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.33%—Broadcom TcpreplayFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora21/12/202317/6/2026
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service…
ModificadaMedia (5.5)0.32%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora21/12/202317/6/2026
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of…
ModificadaMedia (5.3)1.4%—LibsshFedoraproject FedoraRedhat Enterprise Linux19/12/202317/6/2026
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as…
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaAlta (7.8)0.81%—PerlFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+118/12/202317/6/2026
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
ModificadaAlta (7.5)1.6%—X.org X ServerX.org XwaylandRedhat Enterprise Linux EUSDebian Linux+113/12/202323/6/2026
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
ModificadaAlta (7.8)1.6%—Redhat Enterprise Linux EUSDebian LinuxX.org X ServerX.org Xwayland+113/12/202323/6/2026
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
ModificadaAlta (7.8)0.54%—Redhat AnsibleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Ansible Automation Platform+212/12/202317/6/2026
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
ModificadaMedia (5.4)2.2%💥 ExploitModcluster MOD Proxy ClusterRedhat Enterprise Linux12/12/202319/9/2026
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script…
ModificadaMedia (5.5)0.31%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux11/12/202317/6/2026
A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.
ModificadaMedia (4.4)2.6%—PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+1210/12/202317/6/2026
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific…
ModificadaAlta (8.8)4.3%—PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+1710/12/202317/6/2026
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data.…
ModificadaMedia (4.3)2.8%—PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+1210/12/202323/6/2026
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable…
AnalizadaMedia (5.5)0.32%—Fedoraproject FedoraLinux KernelRedhat Enterprise Linux8/12/202317/6/2026
A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service.
ModificadaAlta (7.1)0.43%—Linux KernelRedhat Enterprise Linux8/12/202325/8/2026
An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
ModificadaAlta (7.1)0.53%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+18/12/202317/6/2026
An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
ModificadaMedia (5.3)0.92%—Redhat LibnbdRedhat Enterprise Linux27/11/202317/6/2026
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
ModificadaMedia (5.5)0.48%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora19/11/202317/6/2026
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
ModificadaMedia (4.7)0.25%—Linux KernelRedhat Enterprise Linux16/11/202317/6/2026
A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or escalate their privileges on the system.
ModificadaMedia (4.3)1.7%—Redhat Enterprise Linux16/11/202317/6/2026
An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).
ModificadaBaja (3.3)0.24%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
ModificadaBaja (3.3)0.28%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
ModificadaCrítica (9.8)1.4%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
ModificadaMedia (5.3)0.56%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
ModificadaMedia (5.3)0.29%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.