Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3733 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.51%—MoodleRedhat Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
The course upload preview contained an XSS risk for users uploading unsafe data.
ModificadaMedia (5.4)1.2%💥 PoCMoodleRedhat Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
ModificadaMedia (5.3)0.54%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
ModificadaMedia (5.4)0.51%—MoodleRedhat Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
ModificadaMedia (4.3)0.43%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
ModificadaAlta (8.8)1.9%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
ModificadaAlta (8.8)1.9%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora9/11/202317/6/2026
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
ModificadaMedia (6.4)0.42%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux9/11/202317/6/2026
A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the returned handle value and trigger a…
ModificadaBaja (3.8)0.52%—Opensc Project OpenscFedoraproject FedoraRedhat Enterprise Linux6/11/202317/6/2026
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses…
ModificadaMedia (6.4)1.3%—Opensc Project OpenscRedhat Enterprise Linux6/11/202317/6/2026
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or…
ModificadaMedia (6.6)1.0%—Opensc Project OpenscRedhat Enterprise Linux6/11/202317/6/2026
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small,…
ModificadaMedia (5.5)0.25%—Linux KernelRedhat Enterprise Linux6/11/20236/8/2026
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
ModificadaMedia (6.5)1.7%—SambaRedhat StorageRedhat Enterprise LinuxRedhat Enterprise Linux EUS+46/11/202317/6/2026
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task,…
ModificadaAlta (7)0.23%—QemuRedhat Enterprise Linux3/11/202317/6/2026
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read…
ModificadaCrítica (9.8)2.4%—SambaRedhat StorageRedhat Enterprise LinuxRedhat Enterprise Linux EUS+13/11/202317/6/2026
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However,…
ModificadaAlta (7)0.23%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Power Little Endian+23/11/202317/6/2026
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
ModificadaAlta (7.5)5.2%—Squid-cache SquidRedhat Enterprise Linux3/11/202317/6/2026
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a…
ModificadaMedia (6.5)1.2%—SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+13/11/202317/6/2026
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then…
ModificadaAlta (7.5)10%—Squid-cache SquidRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+13/11/202317/6/2026
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
ModificadaAlta (7.5)88%—Squid-cache SquidRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+63/11/20237/8/2026
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
ModificadaMedia (5.3)6.2%—Squid-cache SquidRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+43/11/202317/6/2026
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
ModificadaMedia (5.5)0.32%—AvahiRedhat Enterprise Linux2/11/202317/6/2026
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
ModificadaMedia (5.5)0.37%—PHPRedhat Software CollectionsRedhat Enterprise Linux2/11/202317/6/2026
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
ModificadaMedia (5.5)0.32%—AvahiRedhat Enterprise Linux2/11/202317/6/2026
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
ModificadaMedia (5.5)0.33%—AvahiRedhat Enterprise Linux2/11/202317/6/2026
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.