Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3733 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.40% | — | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 5/10/2023 | 17/6/2026 | A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the… | |
| Modificada | Media (6.5) | 1.3% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 5/10/2023 | 17/6/2026 | A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 1.4% | — | LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraRedhat Enterprise Linux | 5/10/2023 | 17/6/2026 | LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 0.35% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 4/10/2023 | 23/6/2026 | A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service. | |
| Modificada | Media (5.5) | 0.31% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 4/10/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service. | |
| Modificada | Alta (8.2) | 0.53% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 4/10/2023 | 17/6/2026 | An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code… | |
| Modificada | Media (5.9) | 0.69% | — | Dogtagpki Network Security Services FOR JavaRedhat Enterprise Linux | 4/10/2023 | 17/6/2026 | A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page). | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Media (4.7) | 0.18% | — | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR Power Little Endian+6 | 3/10/2023 | 17/6/2026 | A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencing pmd_t x. | |
| Modificada | Alta (7.5) | 2.2% | — | Webmproject LibvpxRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora | 30/9/2023 | 17/6/2026 | VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. | |
| Analizada | Alta (8.8) | 49% | ⚠ Explotación activa💥 PoC | Webmproject LibvpxMicrosoft EdgeMicrosoft Edge ChromiumMozilla Firefox+7 | 28/9/2023 | 17/6/2026 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (6.5) | 0.81% | — | Redhat LibnbdRedhat Enterprise Linux | 28/9/2023 | 17/6/2026 | A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that doesn't treat the return value of the nbd_get_size() function correctly. | |
| Modificada | Media (4.7) | 0.27% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora | 28/9/2023 | 17/6/2026 | A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+8 | 27/9/2023 | 17/6/2026 | A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service. | |
| Modificada | Alta (7.8) | 0.51% | — | Linux KernelRedhat Enterprise LinuxDebian Linux | 25/9/2023 | 6/8/2026 | An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the… | |
| Modificada | Alta (7.8) | 0.29% | — | Kubernetes Cri-oRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR Power+3 | 25/9/2023 | 17/6/2026 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | |
| Modificada | Alta (7.1) | 0.41% | — | GNU GawkRedhat Enterprise LinuxFedoraproject Fedora | 25/9/2023 | 17/6/2026 | A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information. | |
| Modificada | Alta (7.5) | 1.6% | — | GNU GlibcRedhat Enterprise Linux | 25/9/2023 | 17/6/2026 | A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash. | |
| Modificada | Media (5.9) | 1.6% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+18 | 18/9/2023 | 14/7/2026 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the… | |
| Modificada | Media (6.5) | 1.7% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+23 | 18/9/2023 | 17/6/2026 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a… | |
| Modificada | Media (5.6) | 0.17% | — | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 13/9/2023 | 17/6/2026 | A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an attacker manages to call the handler multiple times, they can… | |
| Modificada | Media (5.6) | 0.26% | — | QemuRedhat Enterprise Linux | 13/9/2023 | 17/6/2026 | A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service. | |
| Modificada | Media (6.5) | 1.9% | — | QemuRedhat Enterprise LinuxFedoraproject Fedora | 13/9/2023 | 17/6/2026 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remote authenticated client who is able to send a clipboard to the VNC… | |
| Modificada | Alta (8.2) | 0.24% | — | QemuRedhat Enterprise Linux | 13/9/2023 | 17/6/2026 | This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750. | |
| Modificada | Media (5.9) | 1.9% | 💥 PoC | GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems EUS S390x+12 | 12/9/2023 | 17/6/2026 | A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or… |