Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3733 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.27% | — | Linux KernelRedhat Enterprise LinuxDebian Linux | 28/8/2023 | 17/6/2026 | A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak. | |
| Modificada | Media (6.5) | 0.49% | — | KeylimeRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+5 | 25/8/2023 | 17/6/2026 | A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a… | |
| Modificada | Media (5.5) | 0.34% | — | Artifex GhostscriptRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR IBM Z Systems+5 | 23/8/2023 | 17/6/2026 | A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8. | |
| Modificada | Alta (7.8) | 0.24% | — | Redhat Subscription-managerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+16 | 23/8/2023 | 17/6/2026 | A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a… | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelRedhat Enterprise Linux | 21/8/2023 | 17/6/2026 | A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of service due to a missing sanity check during cleanup. | |
| Modificada | Alta (7.1) | 0.24% | — | Linux KernelRedhat Enterprise Linux | 16/8/2023 | 17/6/2026 | A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxnet3_rq_cleanup_all, which could also lead to a kernel… | |
| Modificada | Media (4.3) | 1.1% | — | PostgresqlRedhat Enterprise LinuxDebian Linux | 11/8/2023 | 17/6/2026 | A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows. | |
| Modificada | Alta (8.8) | 1.7% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxDebian Linux | 11/8/2023 | 30/9/2026 | IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE… | |
| Modificada | Media (6.5) | 3.0% | — | Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+530 | 11/8/2023 | 17/6/2026 | Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.7) | 0.65% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+4 | 9/8/2023 | 17/6/2026 | A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file… | |
| Modificada | Media (5.5) | 0.27% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 7/8/2023 | 17/6/2026 | A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 ("tun:… | |
| Modificada | Alta (7.8) | 0.56% | 💥 PoC | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+4 | 7/8/2023 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system. | |
| Modificada | Media (5.5) | 0.23% | — | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 3/8/2023 | 17/6/2026 | A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition. | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+2 | 3/8/2023 | 17/6/2026 | A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition. | |
| Modificada | Media (5.5) | 0.43% | — | Artifex GhostscriptRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 1/8/2023 | 23/6/2026 | A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs. | |
| Modificada | Alta (7.8) | 0.92% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s+4 | 31/7/2023 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system. | |
| Modificada | Media (4.4) | 0.25% | — | Redhat Enterprise LinuxFedoraproject FedoraLinux KernelDebian Linux | 25/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to… | |
| Modificada | Media (4.4) | 0.45% | — | Redhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFVFedoraproject Fedora+2 | 25/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service. | |
| Modificada | Alta (7.8) | 0.34% | — | Linux KernelRedhat Enterprise Linux | 24/7/2023 | 17/6/2026 | An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Media (5.3) | 0.76% | — | Redhat LibvirtRedhat Enterprise Linux | 24/7/2023 | 17/6/2026 | A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon. | |
| Modificada | Alta (7.8) | 0.76% | 💥 PoC | Linux KernelRedhat Enterprise Linux | 24/7/2023 | 21/7/2026 | A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in… | |
| Modificada | Alta (7.1) | 0.42% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu Linux | 24/7/2023 | 17/6/2026 | A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | |
| Modificada | Media (6.5) | 0.32% | — | QemuRedhat Enterprise Linux | 24/7/2023 | 17/6/2026 | A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. | |
| Modificada | Alta (7.5) | 1.4% | — | KeylimeRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+5 | 24/7/2023 | 17/6/2026 | A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections. | |
| Modificada | Media (6.7) | 0.46% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV | 24/7/2023 | 17/6/2026 | A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local privileged user to escalate privileges and… |