Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)11%—Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+86/9/201917/6/2026
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute…
ModificadaMedia (4.4)0.51%—Systemd Project SystemdFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+104/9/201917/6/2026
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be…
ModificadaMedia (5.6)4.5%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+113/9/201917/6/2026
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and…
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ModificadaAlta (8.1)2.7%💥 PoCGoogle AndroidApple Iphone OSApple MAC OS XApple Tvos+14314/8/201917/6/2026
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the…
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+2413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can…
ModificadaAlta (7.8)4.1%—KDE KconfigDebian LinuxFedoraproject FedoraOpensuse Backports SLE+47/8/201917/6/2026
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
ModificadaAlta (7.5)1.4%—Fedoraproject 389 Directory ServerRedhat Enterprise Linux Server EUS2/8/201917/6/2026
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
ModificadaAlta (7.8)0.55%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+52/8/201917/6/2026
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only…
ModificadaAlta (7.8)0.52%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+52/8/201917/6/2026
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an…
ModificadaAlta (7.8)0.47%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+52/8/201917/6/2026
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify…
ModificadaMedia (6.5)2.7%—Icedtea-web Project Icedtea-webRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+231/7/201917/6/2026
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
ModificadaMedia (5)2.2%—Clusterlabs Fence-agentsRedhat Enterprise LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation30/7/201917/6/2026
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM…
ModificadaAlta (7.5)2.7%—Linux KernelRedhat Developer ToolsRedhat MRG RealtimeRedhat Enterprise Linux+1630/7/201917/6/2026
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any…
ModificadaAlta (7.4)1.5%—Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+130/7/201917/6/2026
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the…
ModificadaMedia (4.9)1.9%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability…
ModificadaMedia (6.5)2.3%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)2.2%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)2.0%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of…
ModificadaMedia (5.5)1.9%—Oracle MysqlCanonical Ubuntu LinuxRedhat Software CollectionsRedhat Enterprise Linux+323/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…
ModificadaMedia (4.8)2.3%—Oracle JDKOracle JREDebian LinuxOpensuse Leap+923/7/201917/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple…
ModificadaMedia (4.9)2.0%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaBaja (2.2)1.3%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)2.1%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)2.0%—Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+223/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…