Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.84% | — | Redhat Codeready Linux Builder FOR EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUSRedhat Codeready Linux Builder FOR Power Little Endian EUSRedhat Enterprise Linux+18 | 2/1/2024 | 17/6/2026 | A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with… | |
| Modificada | Alta (7.8) | 0.27% | — | Redhat Insights-clientRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Desktop+15 | 1/11/2023 | 17/6/2026 | A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could… | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+18 | 23/10/2023 | 17/6/2026 | The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use… | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+8 | 27/9/2023 | 17/6/2026 | A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service. | |
| Modificada | Media (5.9) | 1.6% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+18 | 18/9/2023 | 14/7/2026 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the… | |
| Modificada | Media (6.5) | 1.7% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+23 | 18/9/2023 | 17/6/2026 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a… | |
| Modificada | Alta (7.8) | 0.24% | — | Redhat Subscription-managerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+16 | 23/8/2023 | 17/6/2026 | A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Alta (7.5) | 8.8% | — | ISC DhcpdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+15 | 1/11/2019 | 17/6/2026 | There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | PHPCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+19 | 28/10/2019 | 17/6/2026 | In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution. | |
| Analizada | Alta (7.8) | 65% | ⚠ Explotación activa💥 Exploit | Apache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+23 | 8/4/2019 | 17/6/2026 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating… |