Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%—Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
ModificadaAlta (7.1)1.6%—VIMRedhat Enterprise LinuxOpensuse FactorySuse Linux Enterprise+425/12/202117/6/2026
vim is vulnerable to Out-of-bounds Read
ModificadaAlta (7.5)1.4%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaAlta (7.5)1.5%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaAlta (7.5)1.4%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaAlta (7.5)1.5%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaAlta (7.1)0.30%—Suse Linux Enterprise ServerOpensuse Factory28/7/202117/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3…
ModificadaCrítica (9.8)1.1%—Opensuse Cryptctl30/6/202117/6/2026
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE…
ModificadaAlta (7.8)0.32%—Opensuse INN10/6/202117/6/2026
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version…
ModificadaAlta (7.8)0.34%—Opensuse Python-postorius10/6/202117/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory…
ModificadaBaja (3.3)1.3%—Opensuse LibsolvOracle Communications Cloud Native Core Policy18/5/202117/6/2026
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
ModificadaAlta (7.8)0.26%—Opensuse Factory5/5/202117/6/2026
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
ModificadaAlta (7)0.35%—Opensuse Cyrus-sasl25/2/202117/6/2026
A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.
ModificadaMedia (6.6)0.30%—Opensuse Openldap211/2/202117/6/2026
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise…
ModificadaMedia (5.4)0.74%—Opensuse Open Build Service11/2/202117/6/2026
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.
ModificadaMedia (6.5)1.2%—Intel ConnmanDebian LinuxOpensuse Leap9/2/202117/6/2026
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
ModificadaAlta (8.8)1.3%—Intel ConnmanDebian LinuxOpensuse Leap9/2/202117/6/2026
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
ModificadaMedia (5.7)0.56%—Intel Ax201 FirmwareIntel Ax200 FirmwareIntel AC 9560 FirmwareIntel AC 9462 Firmware+1123/11/202017/6/2026
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaCrítica (9.8)100%⚠ Explotación activaSaltstack SaltDebian LinuxFedoraproject FedoraOpensuse Leap6/11/202017/6/2026
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
ModificadaMedia (6.3)0.42%—Sddm Project SddmOpensuse LeapDebian LinuxFedoraproject Fedora4/11/202017/6/2026
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example,…
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora3/11/202017/6/2026
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
ModificadaCrítica (9.6)2.4%—Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux3/11/202017/6/2026
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
AnalizadaAlta (8.8)48%⚠ Explotación activaCefsharpGoogle ChromeMicrosoft EdgeMicrosoft Edge Chromium+43/11/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.2%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+13/11/202017/6/2026
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
ModificadaAlta (7.8)0.27%—Google ChromeOpensuse Backports SLEDebian LinuxOpensuse Leap3/11/202017/6/2026
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.