Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.14% | — | Libcap Project LibcapRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/4/2026 | 2/10/2026 | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be… | |
| Modificada | Alta (7.5) | 0.66% | — | GNU Glibc | 30/3/2026 | 14/7/2026 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character… | |
| Modificada | Media (5.4) | 0.32% | — | GNU Glibc | 20/3/2026 | 14/7/2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification. | |
| Modificada | Alta (7.5) | 0.33% | — | GNU Glibc | 20/3/2026 | 14/7/2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a… | |
| Modificada | Media (6.2) | 0.16% | — | GNU Glibc | 11/3/2026 | 14/7/2026 | Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses… | |
| Modificada | Alta (8.7) | 0.40% | — | Amazon Aws-lc-sysAmazon AWS Libcrypto | 2/3/2026 | 15/7/2026 | Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0. | |
| Analizada | Alta (8.2) | 0.48% | — | Amazon Aws-lc-fips-sysAmazon Aws-lc-sysAmazon AWS Libcrypto | 2/3/2026 | 17/6/2026 | Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not… | |
| Modificada | Alta (8.7) | 0.40% | — | Amazon Aws-lc-sysAmazon AWS Libcrypto | 2/3/2026 | 15/7/2026 | Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC… | |
| Aplazada | Media (4.8) | 0.25% | — | GNU GlibcAI | 18/2/2026 | 17/6/2026 | An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions. | |
| Analizada | Alta (7.5) | 0.50% | — | GNU Glibc | 20/1/2026 | 17/6/2026 | Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. | |
| Analizada | Alta (7.5) | 0.63% | — | GNU Glibc | 15/1/2026 | 17/6/2026 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver. | |
| Analizada | Alta (8.4) | 0.39% | — | GNU Glibc | 14/1/2026 | 17/6/2026 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the… | |
| Analizada | Alta (8.2) | 0.75% | — | Libcoap | 31/12/2025 | 23/9/2026 | libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A remote attacker can trigger a crash and potentially achieve remote code… | |
| Analizada | Media (6.5) | 0.26% | — | Libcoap | 8/12/2025 | 17/6/2026 | A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead… | |
| Analizada | Media (4.3) | 0.27% | — | Libcoap | 24/11/2025 | 17/6/2026 | Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns NULL. | |
| Analizada | Media (4.3) | 0.27% | — | Libcoap | 24/11/2025 | 17/6/2026 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. | |
| Analizada | Media (4.3) | 0.27% | — | Libcoap | 24/11/2025 | 17/6/2026 | Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_ex_data_X509_STORE_CTX_idx() to return -1. | |
| Analizada | Media (4.3) | 0.27% | — | Libcoap | 24/11/2025 | 17/6/2026 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. | |
| Analizada | Media (4.3) | 0.27% | — | Libcoap | 24/11/2025 | 17/6/2026 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. | |
| Analizada | Media (4.3) | 0.27% | — | Libcoap | 24/11/2025 | 17/6/2026 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. | |
| Analizada | Alta (7.5) | 0.24% | — | Libcoap | 24/11/2025 | 17/6/2026 | Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size parameter. | |
| Analizada | Alta (7.5) | 0.24% | — | Libcoap | 24/11/2025 | 17/6/2026 | NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL. | |
| Analizada | Alta (7.5) | 0.38% | — | Libcoap | 24/11/2025 | 17/6/2026 | NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_data() to return NULL. | |
| Analizada | Baja (3.3) | 0.21% | — | Openprinting Cups-filtersOpenprinting Libcupsfilters | 12/11/2025 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In cups-filters prior to 1.28.18, by crafting a PDF file with a large `MediaBox` value, an attacker can cause CUPS-Filter 1.x’s `pdftoraster` tool to write beyond the… | |
| Analizada | Baja (3.7) | 0.45% | — | Openprinting Cups-filtersOpenprinting Libcupsfilters | 12/11/2025 | 17/6/2026 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. In CUPS-Filters versions up to and including 1.28.17 and… |