Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1062 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaMedia (5.5)0.21%—SAP Host Agent11/5/202217/6/2026
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
ModificadaAlta (7.5)2.2%—Ghost Sqlite31/5/202217/6/2026
The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.
ModificadaAlta (7.8)1.2%—Artifex GhostscriptDebian Linux25/4/202217/6/2026
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
ModificadaAlta (7.8)0.84%—Artifex Ghostpcl14/4/202217/6/2026
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been…
ModificadaCrítica (9.8)3.5%—Ghost12/4/20229/7/2026
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.
ModificadaCrítica (9.8)4.0%—Ghost12/4/202217/6/2026
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated users. The uploading of SVG files to…
ModificadaAlta (8.8)68%💥 PoCLinux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+2625/3/202217/6/2026
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access…
AnalizadaAlta (7.8)0.38%—Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+3425/3/20225/8/2026
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
AnalizadaAlta (7.8)1.2%💥 PoCLinux KernelFedoraproject FedoraRedhat Build OF QuarkusRedhat Developer Tools+2618/3/202226/8/2026
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
AnalizadaAlta (7.8)93%⚠ Explotación activa💥 ExploitLinux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2510/3/202217/6/2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read…
ModificadaAlta (7.8)0.34%—Linux KernelFedoraproject FedoraDebian LinuxRedhat Virtualization Host+1910/3/202217/6/2026
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
ModificadaAlta (8.8)0.66%💥 PoCLinux KernelFedoraproject FedoraRedhat Software CollectionsRedhat Openstack+224/3/202217/6/2026
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable…
ModificadaMedia (5.5)0.53%—Linux KernelFedoraproject FedoraDebian LinuxRedhat Build OF Quarkus+194/3/202217/6/2026
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.
AnalizadaAlta (7.8)5.5%⚠ Explotación activa💥 ExploitNetapp H300s FirmwareNetapp H410c FirmwareNetapp H410s FirmwareNetapp H500s Firmware+233/3/202217/6/2026
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
ModificadaMedia (5.5)0.39%—Redhat Ansible Automation Platform Early AccessRedhat Ansible EngineRedhat OpenstackRedhat Virtualization+53/3/202217/6/2026
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
ModificadaAlta (7)0.43%—Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+283/3/202217/6/2026
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
ModificadaAlta (8.8)74%💥 PoCSambaDebian LinuxCanonical Ubuntu LinuxSynology Diskstation Manager+1921/2/202217/6/2026
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially…
ModificadaAlta (8.1)1.6%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2118/2/202217/6/2026
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
ModificadaMedia (5.9)1.8%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2018/2/202217/6/2026
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
ModificadaCrítica (9.9)84%—Artifex GhostscriptFedoraproject Fedora16/2/202217/6/2026
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this…
ModificadaAlta (7.1)1.7%—Linux KernelRedhat 3scaleRedhat Virtualization HostFedoraproject Fedora+1516/2/202217/6/2026
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality,…
AnalizadaAlta (7.8)24%⚠ Explotación activa💥 ExploitPolkit Project PolkitDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+216/2/202217/6/2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to…
ModificadaAlta (8.1)0.82%—Wasmcloud Host Runtime21/1/202217/6/2026
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for inbound invocations, but with this…
ModificadaAlta (7.8)0.49%—Advanced Intrusion Detection Environment Project Advanced Intrusion Detection EnvironmentRedhat Ovirt-nodeRedhat Virtualization HostRedhat Enterprise Linux+320/1/202217/6/2026
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
Orbitaley — Vulnerabilidades