Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
6914 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.30% | — | Redhat AnsibleRedhat Enterprise LinuxRedhat Ansible Automation PlatformRedhat Ansible Developer+2 | 6/2/2024 | 17/6/2026 | An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values. | |
| Modificada | Alta (7.8) | 0.56% | — | VIMFedoraproject Fedora | 5/2/2024 | 17/6/2026 | Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. | |
| Modificada | Alta (8.6) | 19% | 💥 Exploit | Linuxfoundation RuncFedoraproject Fedora | 31/1/2024 | 17/9/2026 | runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for… | |
| Modificada | Media (5.3) | 2.7% | — | GNU GlibcFedoraproject Fedora | 31/1/2024 | 17/6/2026 | An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in… | |
| Modificada | Alta (7.5) | 3.2% | — | GNU GlibcFedoraproject Fedora | 31/1/2024 | 17/6/2026 | An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to… | |
| Modificada | Alta (7.8) | 4.8% | 💥 PoC | GNU GlibcFedoraproject Fedora | 31/1/2024 | 17/6/2026 | A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is… | |
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa💥 PoC | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeFedoraproject Fedora | 30/1/2024 | 17/6/2026 | Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.89% | — | Google ChromeFedoraproject Fedora | 30/1/2024 | 17/6/2026 | Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.95% | — | Google ChromeFedoraproject Fedora | 30/1/2024 | 17/6/2026 | Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (6.5) | 1.0% | — | AiohttpFedoraproject Fedora | 29/1/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional… | |
| Modificada | Alta (7.5) | 77% | 💥 Exploit | AiohttpFedoraproject Fedora | 29/1/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the… | |
| Modificada | Alta (7.5) | 1.4% | — | Gabriels FTP Server Project Gabriels FTP Server | 29/1/2024 | 17/6/2026 | A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument USERNAME leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended… | |
| Modificada | Media (5.1) | 0.40% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase. | |
| Modificada | Media (5.5) | 0.40% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase. | |
| Modificada | Media (5.5) | 0.41% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.44% | — | Redhat ShimFedoraproject FedoraRedhat Enterprise Linux | 29/1/2024 | 17/6/2026 | A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain… | |
| Modificada | Alta (7.4) | 0.44% | — | Redhat ShimFedoraproject Fedora | 29/1/2024 | 26/6/2026 | A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory… | |
| Modificada | Alta (7.5) | 1.2% | — | Linux KernelFedoraproject FedoraDebian Linux | 29/1/2024 | 17/6/2026 | Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts are directly translated into what Linux… | |
| Modificada | Media (6.1) | 0.46% | — | Webcalendar Project Webcalendar | 25/1/2024 | 17/6/2026 | WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php. | |
| Modificada | Media (6.5) | 0.33% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.38% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.48% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (4.3) | 0.58% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low) | |
| Modificada | Media (4.3) | 0.41% | — | Google ChromeFedoraproject Fedora | 24/1/2024 | 17/6/2026 | Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low) |