Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.64%—Roundcube WebmailFedoraproject FedoraDebian Linux6/11/202317/6/2026
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
ModificadaCrítica (9.8)2.4%—SambaRedhat StorageRedhat Enterprise LinuxRedhat Enterprise Linux EUS+13/11/202317/6/2026
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However,…
ModificadaMedia (6.5)1.2%—SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+13/11/202317/6/2026
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then…
ModificadaMedia (6.5)1.1%—SambaFedoraproject Fedora3/11/202317/6/2026
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs")…
AnalizadaAlta (8.1)1.1%—Linux KernelFedoraproject Fedora3/11/202317/6/2026
An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the…
ModificadaAlta (7.5)1.1%—Python PillowFedoraproject Fedora3/11/202317/6/2026
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
ModificadaAlta (7.5)1.5%—Djangoproject DjangoFedoraproject Fedora3/11/202317/6/2026
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are…
ModificadaAlta (7)0.20%—Schedmd SlurmFedoraproject Fedora3/11/202317/6/2026
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
ModificadaAlta (7.5)1.5%—Djangoproject DjangoFedoraproject Fedora3/11/202317/6/2026
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
ModificadaMedia (4.3)0.63%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
ModificadaMedia (4.3)0.65%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
ModificadaAlta (8.8)1.3%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium)
ModificadaAlta (8.8)1.2%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)1.0%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
ModificadaAlta (8.8)1.1%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.65%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)1.0%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.94%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.94%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
ModificadaAlta (8.8)1.3%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)7.2%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.1)1.1%—Google ChromeDebian LinuxFedoraproject Fedora1/11/202317/6/2026
Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
ModificadaMedia (5.3)0.90%—Matrix SynapseFedoraproject Fedora31/10/202317/6/2026
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a…
ModificadaBaja (3.3)0.67%—RmagickFedoraproject Fedora30/10/202317/6/2026
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
ModificadaAlta (7.5)0.67%—Vmware Open VM ToolsDebian LinuxVmware ToolsFedoraproject Fedora27/10/202317/6/2026
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that…