Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
10.164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.30% | — | Linux KernelDebian Linux | 9/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: pm: cpupower: bench: Prevent NULL dereference on malloc failure If malloc returns NULL due to low memory, 'config' pointer can be NULL. Add a check to prevent NULL dereference. | |
| Analizada | Alta (7.8) | 0.33% | — | Linux KernelDebian Linux | 9/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixed warning on PM resume as shown below caused due to uninitialized struct nand_operation that checks chip select field : WARN_ON(op->cs >= nanddev_ntargets(&chip->base) The fix uses the higher level… | |
| Analizada | Alta (7.8) | 0.33% | — | Linux KernelDebian Linux | 9/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal emptiness is not determined by sb->s_sequence == 0 but rather by sb->s_start == 0 (which is set a few lines above). Furthermore 0 is a valid transaction ID so the check can spuriously trigger. Remove the… | |
| Analizada | Media (5.5) | 0.31% | — | Linux KernelDebian Linux | 9/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: Fix reference leak in pci_register_host_bridge() If device_register() fails, call put_device() to give up the reference to avoid a memory leak, per the comment at device_register(). Found by code review. [bhelgaas: squash Dan Carpenter's double… | |
| Modificada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate() cpufreq_cpu_get_raw() can return NULL when the target CPU is not present in the policy->cpus mask. scmi_cpufreq_get_rate() does not check for this case, which results in a NULL pointer… | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate() cpufreq_cpu_get_raw() can return NULL when the target CPU is not present in the policy->cpus mask. scpi_cpufreq_get_rate() does not check for this case, which results in a NULL pointer… | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL pointer dereference in tipc_mon_reinit_self() syzbot reported: There is a racing condition between workqueue created when enabling bearer and another thread created when disabling bearer right after that as follow: | |
| Modificada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 8/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too Similarly to the previous patch, we need to safe guard hfsc_dequeue() too. But for this one, we don't have a reliable reproducer. | |
| Modificada | Media (5.5) | 0.40% | — | Linux KernelDebian Linux | 8/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: xen-netfront: handle NULL returned by xdp_convert_buff_to_frame() The function xdp_convert_buff_to_frame() may return NULL if it fails to correctly convert the XDP buffer into an XDP frame due to memory constraints, internal errors, or invalid data.… | |
| Analizada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() With ACPI in place, gicv2m_get_fwnode() is registered with the pci subsystem as pci_msi_get_fwnode_cb(), which may get invoked at runtime during a PCI host bridge probe. But, the call back… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for invalid PMD LoongArch's huge_pte_offset() currently returns a pointer to a PMD slot even if the underlying entry points to invalid_pte_table (indicating no mapping). Callers like smaps_hugetlb_range()… | |
| Analizada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mcb: fix a double free bug in chameleon_parse_gdd() In chameleon_parse_gdd(), if mcb_device_register() fails, 'mdev' would be released in mcb_device_register() via put_device(). Thus, goto 'err' label and free 'mdev' again causes a double free. Just… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget Under PREEMPT_RT the deadlock can be readily triggered by heavy network traffic, for example using "iperf --bidir" over NCM ethernet link. The deadlock occurs because the threaded interrupt handler gets… | |
| Analizada | Media (5.5) | 0.19% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: ci_hdrc_imx: fix usbmisc handling usbmisc is an optional device property so it is totally valid for the corresponding data->usbmisc_data to have a NULL value. Check that before dereferencing the pointer. Found by Linux Verification… | |
| Analizada | Alta (7.8) | 0.23% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: check that event count does not exceed event buffer length The event count is read from register DWC3_GEVNTCOUNT. There is a check for the count being zero, but not for exceeding the event buffer length. Check that event count does… | |
| Analizada | Media (5.5) | 0.21% | — | Linux KernelDebian Linux | 8/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: null - Use spin lock instead of mutex As the null algorithm may be freed in softirq context through af_alg, use spin locks instead of mutexes to protect the default null algorithm. | |
| Analizada | Alta (7.5) | 0.37% | — | Oneidentity Syslog-ngDebian Linux | 7/5/2025 | 17/6/2026 | syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided / invalidated. This issue could have an impact on TLS… | |
| Modificada | Alta (7.8) | 0.45% | — | Linux KernelDebian Linux | 2/5/2025 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix WRITE_SAME No Data Buffer crash In newer version of the SBC specs, we have a NDOB bit that indicates there is no data buffer that gets written out. If this bit is set using commands like "sg_write_same --ndob" we will crash in… | |
| Analizada | Baja (2.3) | 0.79% | — | Ublockorigin Ublock OriginDebian Linux | 2/5/2025 | 17/6/2026 | A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack… | |
| Modificada | Alta (7.8) | 0.23% | — | Linux KernelDebian Linux | 2/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() After making all ->qlen_notify() callbacks idempotent, now it is safe to remove the check of qlen!=0 from both fq_codel_dequeue() and codel_qdisc_dequeue(). | |
| Modificada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 2/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class handling This patch fixes a Use-After-Free vulnerability in the HFSC qdisc class handling. The issue occurs due to a time-of-check/time-of-use condition in hfsc_change_class() when working with certain… | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 1/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Prevent potential NULL dereference The btrtl_initialize() function checks that rtl_load_file() either had an error or it loaded a zero length file. However, if it loaded a zero length file then the error code is not set correctly. It… | |
| Modificada | Media (5.5) | 0.24% | — | Linux KernelDebian Linux | 1/5/2025 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: net: mctp: Set SOCK_RCU_FREE Bind lookup runs under RCU, so ensure that a socket doesn't go away in the middle of a lookup. | |
| Modificada | Alta (7.8) | 0.22% | — | Linux KernelDebian Linux | 1/5/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix nested key length validation in the set() action It's not safe to access nla_len(ovs_key) if the data is smaller than the netlink header. Check that the attribute is OK first. | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelDebian Linux | 1/5/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: cxgb4: fix memory leak in cxgb4_init_ethtool_filters() error path In the for loop used to allocate the loc_array and bmap for each port, a memory leak is possible when the allocation for loc_array succeeds, but the allocation for bmap fails. This is… |