Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.9% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 5/7/2023 | 17/6/2026 | Vulnerabilidad de Escalada de Privilegios Locales de Use-After-Free de Linux nftables; 'nft_chain_lookup_byid()' no pudo comprobar si una cadena estaba activa y CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red | |
| Modificada | Alta (7.5) | 3.0% | — | Djangoproject DjangoDebian LinuxFedoraproject Fedora | 3/7/2023 | 17/6/2026 | In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs. | |
| Modificada | Alta (7.5) | 3.9% | — | Nodejs Node.jsFedoraproject Fedora | 30/6/2023 | 8/10/2026 | The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence… | |
| Modificada | Media (5.7) | 0.55% | 💥 PoC | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 30/6/2023 | 17/6/2026 | A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%. | |
| Modificada | Crítica (10) | 0.87% | — | PlantumlFedoraproject Fedora | 27/6/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. | |
| Modificada | Media (5.3) | 0.87% | — | PlantumlFedoraproject Fedora | 27/6/2023 | 17/6/2026 | Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. | |
| Modificada | Alta (7.8) | 3.9% | 💥 PoC | Artifex GhostscriptDebian LinuxFedoraproject Fedora | 25/6/2023 | 28/8/2026 | Artifex Ghostscript a través de 10.01.2 maneja mal la validación de permisos para dispositivos pipe (con el prefijo %pipe% o el prefijo | pipe character). | |
| Modificada | Media (4.4) | 0.26% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+5 | 23/6/2023 | 17/6/2026 | A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic. | |
| Modificada | Alta (7.1) | 1.4% | — | Openprinting CupsFedoraproject FedoraDebian LinuxApple Macos | 22/6/2023 | 17/6/2026 | OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is… | |
| Modificada | Alta (7.5) | 2.5% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33… | |
| Modificada | Alta (7.5) | 3.6% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of… | |
| Modificada | Media (5.5) | 0.50% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.37% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.26% | — | KubernetesFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This… | |
| Modificada | Alta (7.5) | 2.0% | — | Apache Traffic ServerDebian LinuxFedoraproject Fedora | 14/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through… | |
| Modificada | Alta (8.8) | 13% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 14% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Baja (3.9) | 14% | ⚠ Explotación activa | Vmware ToolsDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada. | |
| Modificada | Media (5.5) | 0.20% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 12/6/2023 | 17/6/2026 | A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service. | |
| Modificada | Media (5.4) | 0.69% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 9/6/2023 | 17/6/2026 | Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or… | |
| Modificada | Alta (7.2) | 1.2% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 9/6/2023 | 17/6/2026 | schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code. | |
| Modificada | Media (5.3) | 0.53% | — | GrpcFedoraproject Fedora | 9/6/2023 | 17/6/2026 | gRPC contiene una vulnerabilidad por la que un cliente puede provocar la finalización de la conexión entre un proxy HTTP2 y un servidor gRPC. Un error de codificación en base64 para cabeceras con sufijo "-bin" provocará la desconexión por parte del servidor gRPC, pero suele estar permitido por los proxies HTTP2. Se… |