Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
4278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Canonical Snap-confineAI | 21/7/2026 | 22/7/2026 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than… | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Canonical SnapdAI | 21/7/2026 | 22/7/2026 | A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution… | |
| Pendiente de análisis | Media (5.6) | 0.13% | — | Canonical SnapdAISystemd-userdbdAI | 21/7/2026 | 22/7/2026 | An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL… | |
| Pendiente de análisis | Media (5) | 0.21% | — | Canonical Ubuntu PRO ClientAI | 16/7/2026 | 16/7/2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying… | |
| Pendiente de análisis | Crítica (9) | 0.53% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the… | |
| Analizada | Media (5) | 0.28% | — | Canonical LXD | 26/6/2026 | 6/7/2026 | In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a URL source, the… | |
| Analizada | Alta (7.2) | 0.63% | — | Canonical LXD | 26/6/2026 | 2/7/2026 | A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by… | |
| Analizada | Media (6.5) | 0.55% | — | Canonical LXD | 26/6/2026 | 2/7/2026 | Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field. | |
| Analizada | Crítica (9.6) | 0.29% | — | Canonical LXD | 26/6/2026 | 2/7/2026 | Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled. | |
| Pendiente de análisis | Crítica (9) | 0.14% | — | Canonical AdsysAISambaAI | 22/6/2026 | 22/6/2026 | An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP… | |
| Aplazada | Media (5.1) | 0.30% | — | Canonical MicrocephAI | 19/6/2026 | 22/6/2026 | Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement.… | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets. | |
| Analizada | Media (5.5) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic. | |
| Analizada | Media (5.5) | 0.10% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock. | |
| Analizada | Alta (7.8) | 0.15% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the… | |
| Analizada | Media (5.5) | 0.15% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects. | |
| Analizada | Alta (7.8) | 0.17% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses. | |
| Analizada | Media (6.1) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to… | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. | |
| Analizada | Media (5.5) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion. | |
| Analizada | Alta (8.4) | 0.45% | — | Canonical Multipass | 28/5/2026 | 17/6/2026 | An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain… |