Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
8554 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.10% | — | Linux KernelRedhat Enterprise Linux | 25/6/2026 | 15/7/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4 [airlied: just added some comments on how to reenable] On-list because the cat is out of the bag and we're clearly not good enough to figure this out in private. The story thus far: 5e28b7b94408… | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 9/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the… | |
| Modificada | Crítica (9.8) | 0.53% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 16/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - Avoid potential future misuse after pskb_pull() call. | |
| Modificada | Crítica (9.8) | 0.37% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 10/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_content_len() while at it. | |
| Modificada | Alta (7.8) | 0.19% | — | Linux KernelRedhat Enterprise Linux | 24/6/2026 | 17/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_ops that are used to register the callbacks. However, in v5.14 I added… | |
| Analizada | Media (4.4) | 0.16% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 6/7/2026 | A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first… | |
| Analizada | Media (4.3) | 0.39% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 1/7/2026 | A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream… | |
| Analizada | Media (6.5) | 0.39% | — | Redhat Enterprise Linux | 23/6/2026 | 1/7/2026 | A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET requests. This causes credentials to be exposed in web server access logs,… | |
| Analizada | Media (5.5) | 0.16% | — | Redhat Enterprise Linux | 23/6/2026 | 31/8/2026 | Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into result["passphrase"] with no output suppression, no no_log… | |
| Analizada | Media (5.3) | 0.40% | — | Redhat Enterprise LinuxThekelleys Dnsmasq | 23/6/2026 | 31/8/2026 | An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via… | |
| Modificada | Media (6.1) | 0.13% | — | Openbsd OpensshRedhat Enterprise Linux | 23/6/2026 | 7/10/2026 | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the… | |
| Modificada | Baja (3.7) | 0.65% | — | Openbsd OpensshRedhat Hardened ImagesRedhat Enterprise Linux | 23/6/2026 | 24/9/2026 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving… | |
| Modificada | Media (6.5) | 0.60% | — | Openbsd OpensshRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 23/6/2026 | 7/10/2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters.… | |
| Analizada | Media (5.9) | 0.53% | — | Redhat Openshift Container PlatformRedhat Enterprise LinuxThekelleys Dnsmasq | 22/6/2026 | 31/8/2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may… | |
| Analizada | Media (4.8) | 0.36% | — | Redhat Enterprise LinuxGnome Libsoup | 22/6/2026 | 8/7/2026 | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206… | |
| Aplazada | Crítica (9.3) | 0.66% | — | FileriseAI | 19/6/2026 | 10/8/2026 | FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename and REGEX_FILE_NAME, which permit URL-encoded… | |
| Modificada | Media (5) | 0.35% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 18/6/2026 | 30/6/2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP… | |
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Analizada | Media (5.4) | 0.23% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 17/6/2026 | 28/6/2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace… | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 17/6/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS… | |
| Analizada | Alta (7.1) | 0.38% | — | Oracle Enterprise Asset Management | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Asset Management | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset… | |
| Analizada | Crítica (9.3) | 0.19% | — | Oracle JD Edwards Enterpriseone Tools | 17/6/2026 | 18/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes… | |
| Analizada | Crítica (9.3) | 0.35% | — | Oracle JD Edwards Enterpriseone Tools | 17/6/2026 | 17/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle JD Edwards Enterpriseone JOB Cost | 17/6/2026 | 18/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Oracle JD Edwards (component: Job Costing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Project Costing.… |