Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.53%—Polkit Project PolkitRedhat Enterprise LinuxFedoraproject FedoraCanonical Ubuntu Linux+221/2/202217/6/2026
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
ModificadaCrítica (9.8)4.8%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
ModificadaAlta (7.5)4.7%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
ModificadaMedia (6.5)3.3%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
ModificadaCrítica (9.8)34%💥 PoCLibexpat Project LibexpatDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+116/2/202217/6/2026
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
ModificadaCrítica (9.8)5.0%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+216/2/202217/6/2026
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
ModificadaAlta (7.5)8.3%—PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+69/2/202217/6/2026
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a…
ModificadaAlta (8.1)6.2%—Printerlogic Virtual AppliancePrinterlogic WEB Stack31/1/20229/7/2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.
AnalizadaAlta (7.8)94%⚠ Explotación activa💥 ExploitPolkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2628/1/202215/8/2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends…
ModificadaAlta (7.8)0.24%—Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+321/1/202217/6/2026
The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.
ModificadaAlta (8)0.36%—Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+321/1/202217/6/2026
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
ModificadaMedia (5.5)0.26%—Oracle Http ServerOracle ZFS Storage Appliance KITOracle Solaris19/1/202217/6/2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this…
ModificadaMedia (5.3)2.8%—Oracle GraalvmOracle Http ServerOracle JDKOracle JRE+1519/1/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker…
ModificadaAlta (7.5)1.3%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software11/1/202211/8/2026
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS…
ModificadaAlta (7.5)1.3%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software11/1/202211/8/2026
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS…
ModificadaMedia (6.1)25%💥 ExploitBeyondtrust Appliance Base Software5/1/202217/6/2026
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.
ModificadaAlta (7.5)3.8%—WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+130/12/202117/6/2026
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
ModificadaAlta (7.5)3.8%—WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+130/12/202117/6/2026
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
ModificadaMedia (5.5)1.5%—WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT30/12/202117/6/2026
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
ModificadaAlta (7.5)3.2%—WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT30/12/202117/6/2026
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
ModificadaAlta (7.5)3.8%—WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+130/12/202117/6/2026
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
ModificadaMedia (6.7)0.24%—Dell Powerpath Management Appliance21/12/202117/6/2026
Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.
ModificadaMedia (6.7)0.22%—Dell EMC Avamar ServerDell EMC Powerprotect Data Protection Appliance21/12/202117/6/2026
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application…
AnalizadaCrítica (9.8)97%💥 ExploitApache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+1020/12/202117/6/2026
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
ModificadaAlta (7.1)2.7%—LxmlFedoraproject FedoraDebian LinuxNetapp Solidfire+713/12/202117/6/2026
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade…