Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

3733 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.29%—Linux KernelRedhat Enterprise Linux29/8/202217/6/2026
A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.
ModificadaAlta (7.8)0.46%—LibmodbusFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux29/8/202217/6/2026
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
ModificadaAlta (7.8)0.33%—QemuRedhat Enterprise Linux29/8/202217/6/2026
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is…
ModificadaMedia (6.7)0.85%💥 PoCEurosoft-uk Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+626/8/202217/6/2026
A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader.…
ModificadaMedia (6.7)1.1%💥 PoCHorizondatasys Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+626/8/202217/6/2026
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this…
ModificadaMedia (6.7)0.98%💥 PoCKidan Cryptopro Securedisk FOR BitlockerRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+626/8/202217/6/2026
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this…
ModificadaMedia (5.5)0.32%—Virglrenderer Project VirglrendererRedhat Enterprise Linux26/8/202217/6/2026
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information…
ModificadaMedia (5.5)0.30%—Linux KernelRedhat Enterprise LinuxDebian Linux26/8/202217/6/2026
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
ModificadaMedia (4.4)0.27%—Linux KernelRedhat Enterprise Linux26/8/202217/6/2026
A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the system.
ModificadaAlta (7)0.77%💥 PoCLinux KernelDebian LinuxRedhat Enterprise Linux26/8/202217/6/2026
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the…
ModificadaMedia (5.5)0.29%—Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+1926/8/202217/6/2026
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
ModificadaMedia (6.7)0.50%—RPMRedhat Enterprise Linux26/8/202217/6/2026
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this…
ModificadaMedia (6.7)0.51%—RPMFedoraproject FedoraRedhat Enterprise Linux25/8/202217/6/2026
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat…
ModificadaMedia (6.4)0.32%—RPMRedhat Enterprise LinuxFedoraproject Fedora25/8/202217/6/2026
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as…
ModificadaAlta (7.8)0.40%—Virglrenderer Project VirglrendererRedhat Enterprise LinuxDebian Linux25/8/202217/6/2026
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
ModificadaBaja (3.3)0.62%—Unzip Project UnzipFedoraproject FedoraRedhat Enterprise Linux24/8/202217/6/2026
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
ModificadaAlta (7.5)1.6%—Dogtagpki Network Security Services FOR JavaRedhat Enterprise LinuxDebian Linux24/8/202217/6/2026
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
ModificadaMedia (6.5)1.7%—GnutlsRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+124/8/202217/6/2026
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.
ModificadaAlta (7.1)1.2%💥 PoCLinux KernelDebian LinuxRedhat Enterprise LinuxNetapp H300s Firmware+424/8/202217/6/2026
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.
ModificadaMedia (5.3)3.2%—PythonDebian LinuxRedhat Software CollectionsRedhat Enterprise Linux+124/8/202217/6/2026
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given…
ModificadaMedia (4.4)0.25%—Linux KernelRedhat Enterprise LinuxDebian Linux24/8/202217/6/2026
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit…
ModificadaMedia (6)0.40%—QemuRedhat Enterprise Linux24/8/202217/6/2026
A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
ModificadaAlta (7.8)0.28%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s Firmware+423/8/202217/6/2026
A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.
ModificadaMedia (5.5)1.7%—Systemd Project SystemdFedoraproject FedoraRedhat Enterprise Linux23/8/202217/6/2026
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
ModificadaMedia (6.5)1.5%💥 PoCRedhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+1023/8/202217/6/2026
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged…