Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.6)1.2%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaAlta (8.8)6.4%💥 PoCGoogle ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+121/5/202017/6/2026
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.6)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaCrítica (9.6)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/5/202017/6/2026
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (8.8)2.0%—Google ChromeDebian LinuxOpensuse Leap21/5/202017/6/2026
Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)3.3%—Google ChromeFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+221/5/202017/6/2026
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7)56%💥 ExploitApache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+2220/5/202025/8/2026
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is…
ModificadaAlta (8.8)2.4%—Mariadb Connector/cOpensuse LeapFedoraproject Fedora20/5/202017/6/2026
libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
ModificadaMedia (4.4)0.47%—Dpdk Data Plane Development KITFedoraproject FedoraOpensuse LeapOracle Enterprise Communications Broker20/5/202017/6/2026
A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.
ModificadaAlta (7.7)2.2%—Dpdk Data Plane Development KITFedoraproject FedoraOpensuse LeapOracle Enterprise Communications Broker20/5/202017/6/2026
A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor…
ModificadaAlta (7.5)3.0%—WiresharkDebian LinuxOpensuse LeapFedoraproject Fedora19/5/202017/6/2026
In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.
ModificadaMedia (6.7)0.38%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+219/5/202017/6/2026
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
ModificadaMedia (6.7)0.38%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+219/5/202017/6/2026
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
ModificadaAlta (7.5)4.5%—Powerdns RecursorFedoraproject FedoraDebian LinuxOpensuse Backports SLE+119/5/202017/6/2026
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritative name servers. The attack uses a crafted reply by an authoritative…
ModificadaMedia (5.4)2.4%💥 PoCBluetooth CoreOpensuse Leap19/5/202017/6/2026
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave…
ModificadaMedia (5.3)1.3%—Opensuse Open Build ServiceDebian Linux19/5/202017/6/2026
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
ModificadaMedia (5.9)93%💥 ExploitISC BindDebian LinuxFedoraproject FedoraOpensuse Leap+119/5/202017/6/2026
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make…
ModificadaAlta (7.5)3.6%—Nlnetlabs UnboundDebian LinuxOpensuse LeapCanonical Ubuntu Linux+119/5/202017/6/2026
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
ModificadaAlta (7.5)3.2%—Nlnetlabs UnboundDebian LinuxOpensuse LeapCanonical Ubuntu Linux+119/5/202017/6/2026
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
ModificadaAlta (7.5)2.4%—Powerdns RecursorFedoraproject FedoraDebian LinuxOpensuse Backports SLE+119/5/202017/6/2026
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
ModificadaMedia (6.5)5.2%—Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2018/5/202017/6/2026
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
ModificadaMedia (5.3)1.3%—LibreofficeOpensuse Leap18/5/202017/6/2026
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format of the recovered document was not LibreOffice's default ODF file…
ModificadaMedia (5.3)0.40%—Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+2115/5/202017/6/2026
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
ModificadaBaja (2.2)2.0%—FreerdpCanonical Ubuntu LinuxOpensuse LeapDebian Linux15/5/202017/6/2026
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.