Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
10.164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.45% | — | Debian Yubiserver | 26/6/2025 | 17/6/2026 | yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf. | |
| Analizada | Crítica (9.8) | 0.38% | — | Debian Yubiserver | 26/6/2025 | 17/6/2026 | yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass. | |
| Analizada | Crítica (9.8) | 0.48% | — | Debian PdnsDebian Linux | 26/6/2025 | 17/6/2026 | pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected. | |
| Analizada | Media (5.6) | 0.34% | — | Debian Matplotlib | 26/6/2025 | 16/6/2026 | Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787. | |
| Modificada | Media (4.7) | 0.15% | — | Linux KernelDebian Linux | 20/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard Tai reported a race condition in PRIO, whenever SFQ perturb timer fires at the wrong time. The race is as follows: CPU 0 CPU 1 [1]: lock root [2]: qdisc_tree_flush_backlog() [3]: unlock root | | [5]:… | |
| Modificada | Alta (7.8) | 0.21% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type algif_hash with MSG_MORE flag set and crypto_ahash_import fails, sk2 is freed. However, it is also freed in af_alg_release, leading to slab-use-after-free error. | |
| Modificada | Media (4.7) | 0.15% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race of buffer access at PCM OSS layer The PCM OSS layer tries to clear the buffer with the silence data at initialization (or reconfiguration) of a stream with the explicit call of snd_pcm_format_set_silence() with runtime->dma_area.… | |
| Analizada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Avoid buffer overflow in current_password_store() If the 'buf' array received from the user contains an empty string, the 'length' variable will be zero. Accessing the 'buf' array element with index 'length - 1' will… | |
| Modificada | Media (5.5) | 0.45% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeout on deleted connection NOPIN response timer may expire on a deleted connection and crash with such logs: Did not receive response to NOPIN on CID: 0, failing connection for I_T Nexus… | |
| Modificada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: protect vq->log_used with vq->mutex The vhost-scsi completion path may access vq->log_base when vq->log_used is already set to false. Assuming the VMM is QEMU. The vq->log_base is from QEMU userpace and can be reclaimed via gfree(). As a… | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: libnvdimm/labels: Fix divide error in nd_label_data_init() If a faulty CXL memory device returns a broken zero LSA size in its memory device information (Identify Memory Device (Opcode 4000h), CXL spec. 3.1, 8.2.9.9.1.1), a divide error occurs in the… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: x86/mm: Check return value from memblock_phys_alloc_range() At least with CONFIG_PHYSICAL_START=0x100000, if there is < 4 MiB of contiguous free memory available at this point, the kernel will crash and burn because memblock_phys_alloc_range() returns… | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: lzo - Fix compression buffer overrun Unlike the decompression code, the compression code in LZO never checked for output overruns. It instead assumes that the caller always provides enough buffer space, disregarding the buffer length provided… | |
| Modificada | Media (5.5) | 0.57% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: rseq: Fix segfault on registration when rseq_cs is non-zero The rseq_cs field is documented as being set to 0 by user-space prior to registration, however this is not currently enforced by the kernel. This can result in a segfault on return to… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: dm cache: prevent BUG_ON by blocking retries on failed device resumes A cache device failing to resume due to mapping errors should not be retried, as the failure leaves a partially initialized policy object. Repeating the resume operation risks… | |
| Modificada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: orangefs: Do not truncate file size 'len' is used to store the result of i_size_read(), so making 'len' a size_t results in truncation to 4GiB on 32-bit systems. | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: dm: fix unconditional IO throttle caused by REQ_PREFLUSH When a bio with REQ_PREFLUSH is submitted to dm, __send_empty_flush() generates a flush_bio with REQ_OP_WRITE | REQ_PREFLUSH | REQ_SYNC, which causes the flush_bio to be throttled by wbt_wait().… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: genirq/msi: Store the IOMMU IOVA directly in msi_desc instead of iommu_cookie The IOMMU translation for MSI message addresses has been a 2-step process, separated in time: This has an inherent lifetime problem for the pointer stored in the cookie that… | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix access outside of user given buffer in pktgen_thread_write() Honour the user given buffer size for the strn_len() calls (otherwise strn_len() will access memory outside of the user given buffer). | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock ... or we risk stealing final mntput from sync umount - raising mnt_count after umount(2) has verified that victim is not busy, but before it has set MNT_SYNC_UMOUNT; in that… | |
| Modificada | Alta (7.8) | 0.54% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done Syzbot reported a slab-use-after-free with the following call trace: After freed the tipc_crypto tx by delete namespace, tipc_aead_encrypt_done may still visit it in cryptd_queue_worker… | |
| Modificada | Alta (7) | 0.20% | — | Debian LinuxLinux Kernel | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_fill_dirent There is a race condition in the readdir concurrency process, which may access the rsp buffer after it has been released, triggering the following KASAN warning. The buggy address belongs to the… | |
| Analizada | Media (4.7) | 0.14% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: virtio_ring: Fix data race by tagging event_triggered as racy for KCSAN syzbot reports a data-race when accessing the event_triggered, here is the simplified stack when the issue occurred: write to 0xffff8881025bc452 of 1 bytes by task 3288 on cpu 0:… | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: set device_caps for 417 The video_device for the MPEG encoder did not set device_caps. Add this, otherwise the video device can't be registered (you get a WARN_ON instead). Not seen before since currently 417 support is disabled, but I… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 18/6/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Set dma_mask for ffa devices Set dma_mask for FFA devices, otherwise DMA allocation using the device pointer lead to following warning: |