Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3733 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.21% | — | Linux KernelRedhat Enterprise Linux | 28/2/2023 | 17/6/2026 | In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_destroy() calls list_del(), but the transaction was never placed on a list -- the list head is all zeroes, this results in a NULL pointer dereference. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Media (5.5) | 0.25% | — | Pesign Project PesignFedoraproject FedoraRedhat Enterprise Linux | 2/2/2023 | 17/6/2026 | A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This… | |
| Modificada | Alta (8.8) | 0.95% | — | Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+9 | 1/2/2023 | 17/6/2026 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters | |
| Modificada | Media (5.5) | 0.44% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise Linux | 27/1/2023 | 17/6/2026 | An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599. | |
| Modificada | Alta (7.5) | 1.3% | — | Libsdl Simple Directmedia LayerRedhat Enterprise Linux | 12/1/2023 | 17/6/2026 | A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected. | |
| Modificada | Alta (7.8) | 0.36% | — | GNU BashRedhat Enterprise Linux | 5/1/2023 | 17/6/2026 | A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems. | |
| Modificada | Alta (7.1) | 1.0% | — | GNU Grub2Redhat Enterprise Linux | 19/12/2022 | 17/6/2026 | When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues.… | |
| Modificada | Alta (7.8) | 1.00% | — | X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 14/12/2022 | 17/6/2026 | A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running… | |
| Modificada | Alta (8.6) | 0.51% | — | GNU Grub2Fedoraproject FedoraRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Power Little Endian EUS+4 | 14/12/2022 | 17/6/2026 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this… | |
| Modificada | Crítica (9.8) | 2.1% | — | Rxvt-unicode Project Rxvt-unicodeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 9/12/2022 | 17/6/2026 | The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set. | |
| Modificada | Media (6.5) | 0.29% | — | QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 29/11/2022 | 17/6/2026 | An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash… | |
| Modificada | Crítica (9.1) | 1.4% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 25/11/2022 | 17/6/2026 | A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP… | |
| Modificada | Media (5.1) | 0.26% | — | KeylimeRedhat Enterprise LinuxFedoraproject Fedora | 22/11/2022 | 17/6/2026 | A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that… | |
| Modificada | Media (5.5) | 0.42% | — | Systemd Project SystemdRedhat Enterprise LinuxFedoraproject Fedora | 8/11/2022 | 17/6/2026 | An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service. | |
| Modificada | Alta (7.5) | 1.4% | — | Jasper Project JasperFedoraproject FedoraRedhat Enterprise Linux | 14/10/2022 | 17/6/2026 | A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Directory ServerRedhat Enterprise LinuxFedoraproject FedoraPort389 389-ds-base+1 | 14/10/2022 | 17/6/2026 | A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514. | |
| Modificada | Media (4.3) | 0.66% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | |
| Modificada | Crítica (9.8) | 1.0% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | A limited SQL injection risk was identified in the "browse list of users" site administration page. | |
| Modificada | Alta (7.1) | 0.64% | — | MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 30/9/2022 | 17/6/2026 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. | |
| Modificada | Media (5.5) | 0.22% | — | IBM Java SDKSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITRedhat Satellite+4 | 29/9/2022 | 17/6/2026 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Media (5.5) | 0.30% | — | QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 29/9/2022 | 17/6/2026 | Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu… | |
| Modificada | Media (6.2) | 0.33% | — | QemuFedoraproject FedoraRedhat VirtualizationRedhat Enterprise Linux Desktop+6 | 29/9/2022 | 17/6/2026 | Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine. | |
| Modificada | Alta (8.6) | 1.0% | — | QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 29/9/2022 | 17/6/2026 | QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process. | |
| Modificada | Media (5.5) | 0.49% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 19/9/2022 | 17/6/2026 | A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. |