Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
317 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Alta (7.5) | 2.3% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+14 | 14/1/2025 | 30/6/2026 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification… | |
| Modificada | Media (6.8) | 1.8% | — | Samba RsyncRedhat Openshift Container PlatformRedhat Enterprise LinuxAlmalinux+5 | 14/1/2025 | 21/8/2026 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to… | |
| Modificada | Alta (7.5) | 8.8% | 💥 PoC | Samba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+18 | 14/1/2025 | 21/9/2026 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. | |
| Aplazada | Alta (7.5) | 0.49% | — | SambaAI | 17/11/2024 | 17/6/2026 | A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creation. This issue occurs because the administrator owns the object due to… | |
| Modificada | Media (6.9) | 0.51% | — | Sambas Akos | 3/9/2024 | 17/6/2026 | Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users. This issue affects AKOS (AkosCepVatandasService): before V2.0; AKOS (TahsilatService): before V1.0.7. | |
| Analizada | Crítica (9.8) | 2.1% | ⚠ Explotación activa | Unitronics Vision1210 FirmwareUnitronics Vision1040 FirmwareUnitronics Vision700 FirmwareUnitronics Vision570 Firmware+13 | 5/12/2023 | 17/6/2026 | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system. | |
| Modificada | Media (6.5) | 1.2% | — | Samba | 7/11/2023 | 17/6/2026 | A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords.… | |
| Modificada | Media (6.5) | 1.7% | — | SambaRedhat StorageRedhat Enterprise LinuxRedhat Enterprise Linux EUS+4 | 6/11/2023 | 17/6/2026 | A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task,… | |
| Modificada | Crítica (9.8) | 2.4% | — | SambaRedhat StorageRedhat Enterprise LinuxRedhat Enterprise Linux EUS+1 | 3/11/2023 | 17/6/2026 | A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, which Samba initiates on demand. However,… | |
| Modificada | Media (6.5) | 1.2% | — | SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+1 | 3/11/2023 | 17/6/2026 | A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then… | |
| Modificada | Media (6.5) | 1.1% | — | SambaFedoraproject Fedora | 3/11/2023 | 17/6/2026 | A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs")… | |
| Modificada | Media (6.5) | 1.6% | — | Samba | 25/10/2023 | 17/6/2026 | A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service. | |
| Modificada | Media (5.9) | 0.44% | — | SambaRedhat StorageRedhat Enterprise LinuxFedoraproject Fedora | 20/7/2023 | 17/6/2026 | A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a… | |
| Modificada | Media (5.3) | 1.3% | — | SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+1 | 20/7/2023 | 17/6/2026 | A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part… | |
| Modificada | Media (5.3) | 61% | — | SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 20/7/2023 | 17/6/2026 | A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of… | |
| Modificada | Alta (7.5) | 62% | — | SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 20/7/2023 | 17/6/2026 | An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing… | |
| Modificada | Media (5.9) | 1.7% | — | SambaRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 20/7/2023 | 17/6/2026 | An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length.… | |
| Modificada | Media (5.9) | 0.48% | — | Samba | 3/4/2023 | 17/6/2026 | The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection. | |
| Modificada | Media (6.5) | 0.57% | — | Samba | 3/4/2023 | 17/6/2026 | The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC. | |
| Modificada | Media (4.3) | 0.72% | — | Samba | 3/4/2023 | 17/6/2026 | A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory. | |
| Modificada | Crítica (9.8) | 0.45% | — | Samba | 6/3/2023 | 17/6/2026 | Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg… | |
| Modificada | Media (5.9) | 0.76% | — | SambaFedoraproject Fedora | 6/3/2023 | 17/6/2026 | A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met. | |
| Modificada | Alta (8.8) | 0.26% | — | Seosamba | 8/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions. | |
| Analizada | Media (4.3) | 1.2% | — | SambaFedoraproject Fedora | 17/1/2023 | 17/6/2026 | An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store. |