Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.9%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux5/7/202317/6/2026
Vulnerabilidad de Escalada de Privilegios Locales de Use-After-Free de Linux nftables; 'nft_chain_lookup_byid()' no pudo comprobar si una cadena estaba activa y CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red
ModificadaAlta (7.5)3.0%—Djangoproject DjangoDebian LinuxFedoraproject Fedora3/7/202317/6/2026
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
ModificadaAlta (7.5)3.9%—Nodejs Node.jsFedoraproject Fedora30/6/20238/10/2026
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence…
ModificadaMedia (5.7)0.55%💥 PoCLinux KernelRedhat Enterprise LinuxFedoraproject Fedora30/6/202317/6/2026
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.
ModificadaCrítica (10)0.87%—PlantumlFedoraproject Fedora27/6/202317/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
ModificadaMedia (5.3)0.87%—PlantumlFedoraproject Fedora27/6/202317/6/2026
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
ModificadaAlta (7.8)3.9%💥 PoCArtifex GhostscriptDebian LinuxFedoraproject Fedora25/6/202328/8/2026
Artifex Ghostscript a través de 10.01.2 maneja mal la validación de permisos para dispositivos pipe (con el prefijo %pipe% o el prefijo | pipe character).
ModificadaMedia (4.4)0.26%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+523/6/202317/6/2026
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
ModificadaAlta (7.1)1.4%—Openprinting CupsFedoraproject FedoraDebian LinuxApple Macos22/6/202317/6/2026
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is…
ModificadaAlta (7.5)2.5%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33…
ModificadaAlta (7.5)3.6%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of…
ModificadaMedia (5.5)0.50%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.35%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.37%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.26%—KubernetesFedoraproject Fedora16/6/202317/6/2026
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This…
ModificadaAlta (7.5)2.0%—Apache Traffic ServerDebian LinuxFedoraproject Fedora14/6/202317/6/2026
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through…
ModificadaAlta (8.8)13%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.94%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)14%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.94%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaBaja (3.9)14%⚠ Explotación activaVmware ToolsDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada.
ModificadaMedia (5.5)0.20%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux12/6/202317/6/2026
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
ModificadaMedia (5.4)0.69%—PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora9/6/202317/6/2026
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or…
ModificadaAlta (7.2)1.2%—PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora9/6/202317/6/2026
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
ModificadaMedia (5.3)0.53%—GrpcFedoraproject Fedora9/6/202317/6/2026
gRPC contiene una vulnerabilidad por la que un cliente puede provocar la finalización de la conexión entre un proxy HTTP2 y un servidor gRPC. Un error de codificación en base64 para cabeceras con sufijo "-bin" provocará la desconexión por parte del servidor gRPC, pero suele estar permitido por los proxies HTTP2. Se…