Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.55% | — | IBM Powervm Hypervisor | 29/7/2021 | 17/6/2026 | The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of… | |
| Modificada | Alta (7) | 0.30% | — | Bitdefender Hypervisor Introspection | 17/12/2020 | 17/6/2026 | Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to the same pointer. If the pointer is located in memory-mapped from the guest space, this may cause a race-condition where the generated code would dereference the same… | |
| Modificada | Media (5.5) | 0.27% | — | Bitdefender Hypervisor Introspection | 17/12/2020 | 17/6/2026 | Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service conditions. | |
| Modificada | Media (5.5) | 0.27% | — | Bitdefender Hypervisor Introspection | 17/12/2020 | 17/6/2026 | Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTaskDumpTree may lead to out-of-bounds read or it could cause DoS due to integer-overflor (IntPeGetDirectory), TOCTOU (IntPeParseUnwindData) or insufficient validations. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat Enterprise VirtualizationRedhat Enterprise Virtualization Hypervisor | 25/2/2020 | 17/6/2026 | VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to… | |
| Modificada | Alta (7.5) | 1.9% | — | Python PyxmlRedhat Enterprise Virtualization HypervisorRedhat Enterprise Linux | 22/11/2019 | 16/6/2026 | PyXML: Hash table collisions CPU usage Denial of Service | |
| Modificada | Alta (7.4) | 0.54% | — | Redhat Enterprise Virtualization Hypervisor | 27/12/2013 | 16/6/2026 | libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings. | |
| Modificada | Media (5.7) | 0.99% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Virtualization Hypervisor | 31/8/2011 | 16/6/2026 | The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to cause a denial of service via crafted VLAN packets that are… | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Enterprise Virtualization Hypervisor | 24/6/2010 | 16/6/2026 | Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks… |