Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 18/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma: Add missing locking Recent kernels complain about a missing lock in k3-udma.c when the lock validator is enabled: This commit adds the missing locking. | |
| Modificada | Alta (7.1) | 0.26% | — | Linux KernelDebian Linux | 8/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be changed resp reduced at runtime where the 'currframe' counter is… | |
| Modificada | Media (5.5) | 0.26% | — | Linux KernelDebian Linux | 8/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is generated for a bcm_op which is in the process to be removed the procfs output might show unreliable data (UAF). As the removal of bcm_op's is already implemented… | |
| Modificada | Media (5.5) | 0.50% | 💥 PoC | Linux KernelDebian Linux | 6/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice To fix both the UAF and the infinite loop, with netem as an hfsc child, check explicitly in hfsc_enqueue whether the class is already in the eltree whenever the HFSC_RSC flag is… | |
| Modificada | Alta (7.8) | 0.23% | — | Linux KernelDebian Linux | 6/6/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() When enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the child qdisc's peek() operation before incrementing sch->q.qlen and sch->qstats.backlog. If the child qdisc… | |
| Analizada | Media (5.3) | 0.75% | — | Djangoproject DjangoDebian Linux | 5/6/2025 | 17/6/2026 | An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or… | |
| Analizada | Alta (7.8) | 0.31% | — | Fossies CatdocDebian Linux | 2/6/2025 | 17/6/2026 | An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (7.8) | 0.31% | — | Fossies CatdocDebian Linux | 2/6/2025 | 17/6/2026 | An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (8.8) | 99% | ⚠ Explotación activa💥 Exploit | Roundcube WebmailDebian Linux | 2/6/2025 | 17/6/2026 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. | |
| Modificada | Media (4.7) | 1.2% | — | Systemd Project SystemdRedhat Openshift Container PlatformRedhat Enterprise LinuxDebian Linux+2 | 30/5/2025 | 1/9/2026 | A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID… | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelDebian Linux | 29/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch replaces the manual Netlink attribute iteration in output_userspace() with nla_for_each_nested(), which ensures that only well-formed attributes are processed. | |
| Modificada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 29/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 contained three macros to handle the region locks: ahash_bucket_start(), ahash_bucket_end() which gave back the start and end hash bucket values belonging to a… | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 29/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for module type kobjects In 'lookup_or_create_module_kobject()', an internal kobject is created using 'module_ktype'. So call to 'kobject_put()' on error handling path causes an attempt to use an uninitialized… | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 29/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer access This patch ensures that the UCSI driver waits for all pending tasks in the ucsi_displayport_work workqueue to finish executing before proceeding with the partner removal. | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 26/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change() Previously, when reducing a qdisc's limit via the ->change() operation, only the main skb queue was trimmed, potentially leaving packets in the gso_skb list. This could result in NULL pointer… | |
| Analizada | Alta (8.8) | 0.85% | — | GstreamerDebian Linux | 22/5/2025 | 17/6/2026 | GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 20/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that on parisc a SIGFPE exception will crash an application with a second SIGFPE in the signal handler. Dave analyzed it, and it happens because glibc uses a double-word floating-point store to atomically… | |
| Analizada | Media (5.5) | 0.23% | — | Linux KernelDebian Linux | 20/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() but dose not check its return value. The 'state.state' and the 'state.bytes' are uninitialized if the… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 20/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: phy: leds: fix memory leak A network restart test on a router led to an out-of-memory condition, which was traced to a memory leak in the PHY LED trigger code. The root cause is misuse of the devm API. The registration function… | |
| Analizada | Media (4.7) | 0.13% | — | Linux KernelDebian Linux | 20/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must be the last action or we can open a chardev whose URBs are still poisoned | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 20/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: qibfs: fix _another_ leak failure to allocate inode => leaked dentry... this one had been there since the initial merge; to be fair, if we are that far OOM, the odds of failing at that particular allocation are low... | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 20/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: fix memory leak in wl1251_tx_work The skb dequeued from tx_queue is lost when wl1251_ps_elp_wakeup fails with a -ETIMEDOUT error. Fix that by queueing the skb back to tx_queue. | |
| Modificada | Alta (7.8) | 0.21% | — | Linux KernelDebian Linux | 20/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overflow Case values introduced in commit 5f78e1fb7a3e ("ASoC: qcom: Add driver support for audioreach solution") cause out of bounds access in arrays of sc7280 driver data (e.g. in case of… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 20/5/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: Input: mtk-pmic-keys - fix possible null pointer dereference In mtk_pmic_keys_probe, the regs parameter is only set if the button is parsed in the device tree. However, on hardware where the button is left floating, that node will most likely be… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 20/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent st_lsm6dsx_read_fifo from falling in an infinite loop in case pattern_len is equal to zero and the device FIFO is not empty. |