Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 42% | — | Net-snmpDebian Linux | 23/12/2025 | 17/6/2026 | net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2. | |
| Analizada | Media (6.9) | 0.14% | — | Ubuntu Python-aptDebian Linux | 5/12/2025 | 25/9/2026 | NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key. | |
| Analizada | Media (6.1) | 0.29% | — | Alinto SogoDebian Linux | 24/11/2025 | 17/6/2026 | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. | |
| Modificada | Alta (7.8) | 0.31% | — | Pdfminer.sixDebian Linux | 10/11/2025 | 17/6/2026 | Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute arbitrary code from a malicious pickle file if provided with a malicious PDF file. The `CMapDB._load_data()` function in pdfminer.six uses… | |
| Analizada | Alta (7.3) | 0.28% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. | |
| Analizada | Alta (7.3) | 0.30% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. | |
| Analizada | Alta (7.8) | 0.58% | — | GimpDebian Linux | 29/10/2025 | 17/6/2026 | GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.83% | — | GimpDebian Linux | 29/10/2025 | 17/6/2026 | GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.58% | — | GimpDebian Linux | 29/10/2025 | 17/6/2026 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees When we don't have a clock specified in the device tree, we have no way to ensure the BAM is on. This is often the case for remotely-controlled or remotely-powered BAM instances. In… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: pcmcia: Add error handling for add_interval() in do_validate_mem() In the do_validate_mem(), the call to add_interval() does not handle errors. If kmalloc() fails in add_interval(), it could result in a null pointer being inserted into the linked… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: avoid divide-by-zero in damon_reclaim_apply_parameters() When creating a new scheme of DAMON_RECLAIM, the calculation of 'min_age_region' uses 'aggr_interval' as the divisor, which may lead to division-by-zero errors. Fix it by… | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Silence warning when chunk allocation fails in trace_pid_write Syzkaller trigger a fault injection warning: We can reproduce the warning by following the steps below: 1. echo 8 >> set_event_notrace_pid. Let tr->filtered_pids owns one pid and… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork. syzbot reported the splat below. [0] The repro does the following: At 5., the data is carried over to the next sendmsg() as it is smaller than the cork_bytes… | |
| Analizada | Alta (7.8) | 0.16% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path If request_irq() in i40e_vsi_request_irq_msix() fails in an iteration later than the first, the error path wants to free the IRQs requested so far. However, it uses the wrong dev_id… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters() Patch series "mm/damon: avoid divide-by-zero in DAMON module's parameters application". DAMON's RECLAIM and LRU_SORT modules perform no validation on user-configured… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer Avoid below overlapping mappings by using a contiguous non-cacheable buffer. | |
| Modificada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 1/10/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err() reports details of an object for further debugging, such as the freelist pointer, redzone, etc. However, if the pointer is invalid, attempting to access object… | |
| Modificada | Media (5.5) | 0.32% | — | Linux KernelDebian Linux | 1/10/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast packet to a tap device, which was added to a bridge, br_nf_local_in() is called to confirm the conntrack. If another conntrack with the same… | |
| Analizada | Alta (7.1) | 0.16% | — | Linux KernelDebian Linux | 1/10/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Initialize the chan_stats array to zero The adapter->chan_stats[] array is initialized in mwifiex_init_channel_scan_gap() with vmalloc(), which doesn't zero out memory. The array is filled in mwifiex_update_chan_statistics() and then… | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Analizada | Media (5.5) | 0.12% | — | Linux KernelDebian Linux | 23/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix recursive semaphore deadlock in fiemap call syzbot detected a OCFS2 hang due to a recursive semaphore on a FS_IOC_FIEMAP of the extent list on a specially crafted mmap file. ocfs2_fiemap() takes a read lock of the ip_alloc_sem semaphore… | |
| Analizada | Alta (7.1) | 0.15% | — | Linux KernelDebian Linux | 23/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory When I did memory failure tests, below panic occurs: The root cause is that unpoison_memory() tries to check the PG_HWPoison flags of an uninitialized page. So… | |
| Modificada | Alta (7.8) | 0.15% | — | Linux KernelDebian Linux | 23/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when open file is released A use-after-free (UAF) vulnerability was identified in the PSI (Pressure Stall Information) monitoring mechanism: Reproduction Steps: 1. Open test/cpu.pressure and establish epoll monitoring 2.… | |
| Modificada | Alta (7.8) | 0.32% | — | Linux KernelDebian Linux | 23/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix invalid accesses to ceph_connection_v1_info There is a place where generic code in messenger.c is reading and another place where it is writing to con->v1 union member without checking that the union member is active (i.e. msgr1 is in… |