Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.45%—Hallowelt Bluespice22/7/202217/6/2026
Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL.
ModificadaMedia (6.4)0.31%—Spice-space UsbredirRedhat Enterprise LinuxFedoraproject FedoraDebian Linux24/2/202217/6/2026
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
ModificadaAlta (8.1)1.3%—Authzed Spicedb11/1/202217/6/2026
SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as "accessible" if it is *not* accessible by…
ModificadaMedia (5.3)2.7%—Spice Project SpiceRedhat Enterprise Linux28/5/202117/6/2026
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
ModificadaMedia (6.1)5.1%💥 ExploitSpiceworks18/12/202017/6/2026
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
ModificadaMedia (6.3)0.33%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora26/11/202017/6/2026
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this…
ModificadaMedia (5.5)0.44%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora26/11/202017/6/2026
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd…
ModificadaMedia (6.4)0.30%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora26/11/202017/6/2026
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this…
ModificadaMedia (5.5)0.50%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora25/11/202017/6/2026
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or…
ModificadaMedia (6.6)2.7%—Spice Project SpiceRedhat OpenstackCanonical Ubuntu LinuxDebian Linux+67/10/202017/6/2026
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when…
ModificadaAlta (8.8)0.59%—Spiceworks15/9/20209/7/2026
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
ModificadaMedia (5.4)0.60%—Spiceworks1/9/20209/7/2026
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.
ModificadaAlta (7.5)1.2%—Spice Project SpiceRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+54/2/201917/6/2026
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
ModificadaAlta (7.2)3.9%—Logicspice FAQ Script22/11/201817/6/2026
Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.
ModificadaAlta (8.8)2.4%—Spice Project Spice11/9/201817/6/2026
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
ModificadaAlta (8.8)3.9%—Spice Project SpiceDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+717/8/201817/6/2026
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
ModificadaAlta (7.5)2.5%—Spice Project SpiceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
ModificadaAlta (8.8)3.8%—Spice Project SpiceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
ModificadaCrítica (9.8)5.2%—Spice-gtk Project Spice-gtk14/3/201817/6/2026
A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be…
ModificadaAlta (7.8)0.42%—Spice-space Spice-vdagentDebian Linux20/1/201817/6/2026
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
ModificadaAlta (8.8)4.2%—Spice Project Spice18/7/201717/6/2026
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
ModificadaMedia (6.5)1.0%—Spice-gtk Project Spice-gtk6/6/201717/6/2026
The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
ModificadaMedia (6.1)1.1%—Spiceworks Desktop10/4/201717/6/2026
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
ModificadaCrítica (9.8)6.7%💥 ExploitSpiceworks6/4/201717/6/2026
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a…
ModificadaAlta (7.1)0.36%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+79/6/201617/6/2026
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
Orbitaley — Vulnerabilidades