Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.2) | 1.7% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read. | |
| Modificada | Media (6.6) | 1.9% | — | FreerdpCanonical Ubuntu LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. | |
| Modificada | Media (6.6) | 2.0% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow. | |
| Modificada | Media (6.5) | 2.7% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read. | |
| Modificada | Media (6.6) | 2.0% | — | FreerdpCanonical Ubuntu LinuxOpensuse LeapDebian Linux | 15/5/2020 | 17/6/2026 | libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. | |
| Modificada | Media (5) | 0.30% | — | Google AndroidDebian LinuxCanonical Ubuntu LinuxLibexif Project Libexif+1 | 14/5/2020 | 17/6/2026 | In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9… | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Media (6.1) | 0.92% | — | Opensuse Open Build ServiceDebian Linux | 13/5/2020 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb. | |
| Modificada | Crítica (9.8) | 4.7% | — | Infradead OpenconnectFedoraproject FedoraDebian LinuxOpensuse Leap | 12/5/2020 | 17/6/2026 | OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c. | |
| Modificada | Alta (7.8) | 1.4% | — | Libemf Project LibemfFedoraproject FedoraOpensuse Leap | 11/5/2020 | 17/6/2026 | libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free. | |
| Modificada | Alta (7.8) | 1.4% | — | Libemf Project LibemfFedoraproject FedoraOpensuse Leap | 11/5/2020 | 17/6/2026 | libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access. | |
| Modificada | Media (5.5) | 1.3% | — | Libemf Project LibemfFedoraproject FedoraOpensuse Leap | 11/5/2020 | 17/6/2026 | libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2). | |
| Modificada | Media (5.5) | 1.1% | — | Libemf Project LibemfFedoraproject FedoraOpensuse Leap | 11/5/2020 | 17/6/2026 | libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2). | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+20 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails. | |
| Modificada | Media (5.5) | 0.65% | — | Linux KernelDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8. | |
| Modificada | Media (5.5) | 0.53% | — | Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 9/5/2020 | 17/6/2026 | exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. | |
| Modificada | Media (6.4) | 0.36% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux+18 | 8/5/2020 | 17/6/2026 | There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it… | |
| Modificada | Media (6.5) | 2.7% | — | GNU MailmanDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 6/5/2020 | 17/6/2026 | /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. | |
| Modificada | Alta (7.5) | 3.5% | — | SambaFedoraproject FedoraOpensuse LeapDebian Linux | 6/5/2020 | 17/6/2026 | A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system… | |
| Modificada | Alta (7.5) | 2.9% | — | GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap | 6/5/2020 | 17/6/2026 | GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. | |
| Modificada | Media (5.5) | 0.33% | — | Linux KernelCanonical Ubuntu LinuxOpensuse Leap | 5/5/2020 | 17/6/2026 | gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue does not grant any access not already available. It is a problem that… | |
| Modificada | Alta (7.8) | 0.45% | — | Linux KernelOpensuse LeapDebian LinuxNetapp Active IQ Unified Manager+18 | 5/5/2020 | 17/6/2026 | An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea. | |
| Modificada | Media (5.3) | 2.0% | — | SambaFedoraproject FedoraOpensuse Leap | 4/5/2020 | 17/6/2026 | A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa💥 Exploit | Roundcube WebmailOpensuse Backports SLEOpensuse Leap | 4/5/2020 | 17/6/2026 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. | |
| Modificada | Crítica (9.8) | 6.7% | 💥 PoC | Roundcube WebmailOpensuse Backports SLEOpensuse Leap | 4/5/2020 | 17/6/2026 | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php. |