Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+5 | 1/1/2022 | 17/6/2026 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. | |
| Modificada | Alta (7.1) | 1.6% | — | VIMRedhat Enterprise LinuxOpensuse FactorySuse Linux Enterprise+4 | 25/12/2021 | 17/6/2026 | vim is vulnerable to Out-of-bounds Read | |
| Modificada | Alta (7.5) | 1.4% | — | Opensuse Libsolv | 2/9/2021 | 17/6/2026 | Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| Modificada | Alta (7.5) | 1.5% | — | Opensuse Libsolv | 2/9/2021 | 17/6/2026 | Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| Modificada | Alta (7.5) | 1.4% | — | Opensuse Libsolv | 2/9/2021 | 17/6/2026 | Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| Modificada | Alta (7.5) | 1.5% | — | Opensuse Libsolv | 2/9/2021 | 17/6/2026 | Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| Modificada | Alta (7.1) | 0.30% | — | Suse Linux Enterprise ServerOpensuse Factory | 28/7/2021 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3… | |
| Modificada | Crítica (9.8) | 1.1% | — | Opensuse Cryptctl | 30/6/2021 | 17/6/2026 | A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE… | |
| Modificada | Alta (7.8) | 0.32% | — | Opensuse INN | 10/6/2021 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version… | |
| Modificada | Alta (7.8) | 0.34% | — | Opensuse Python-postorius | 10/6/2021 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory… | |
| Modificada | Baja (3.3) | 1.3% | — | Opensuse LibsolvOracle Communications Cloud Native Core Policy | 18/5/2021 | 17/6/2026 | Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service | |
| Modificada | Alta (7.8) | 0.26% | — | Opensuse Factory | 5/5/2021 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions. | |
| Modificada | Alta (7) | 0.35% | — | Opensuse Cyrus-sasl | 25/2/2021 | 17/6/2026 | A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions. | |
| Modificada | Media (6.6) | 0.30% | — | Opensuse Openldap2 | 11/2/2021 | 17/6/2026 | A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise… | |
| Modificada | Media (5.4) | 0.74% | — | Opensuse Open Build Service | 11/2/2021 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8. | |
| Modificada | Media (6.5) | 1.2% | — | Intel ConnmanDebian LinuxOpensuse Leap | 9/2/2021 | 17/6/2026 | gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp. | |
| Modificada | Alta (8.8) | 1.3% | — | Intel ConnmanDebian LinuxOpensuse Leap | 9/2/2021 | 17/6/2026 | A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code. | |
| Modificada | Media (5.7) | 0.56% | — | Intel Ax201 FirmwareIntel Ax200 FirmwareIntel AC 9560 FirmwareIntel AC 9462 Firmware+11 | 23/11/2020 | 17/6/2026 | Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Saltstack SaltDebian LinuxFedoraproject FedoraOpensuse Leap | 6/11/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. | |
| Modificada | Media (6.3) | 0.42% | — | Sddm Project SddmOpensuse LeapDebian LinuxFedoraproject Fedora | 4/11/2020 | 17/6/2026 | An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example,… | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora | 3/11/2020 | 17/6/2026 | Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 2.4% | — | Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux | 3/11/2020 | 17/6/2026 | Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| Analizada | Alta (8.8) | 48% | ⚠ Explotación activa | CefsharpGoogle ChromeMicrosoft EdgeMicrosoft Edge Chromium+4 | 3/11/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.2% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 3/11/2020 | 17/6/2026 | Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet. | |
| Modificada | Alta (7.8) | 0.27% | — | Google ChromeOpensuse Backports SLEDebian LinuxOpensuse Leap | 3/11/2020 | 17/6/2026 | Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem. |