Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.6) | 0.39% | — | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 27/3/2023 | 17/6/2026 | A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.8) | 0.90% | — | X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 27/3/2023 | 17/6/2026 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote… | |
| Modificada | Baja (2.3) | 0.20% | — | Linux KernelRedhat Enterprise LinuxFedoraproject Fedora | 27/3/2023 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdma_cm device node. While this access is unlikely to leak sensitive user information, it can be further used to… | |
| Modificada | Alta (7.1) | 0.70% | — | DinoFedoraproject FedoraDebian Linux | 24/3/2023 | 17/6/2026 | Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information. | |
| Modificada | Media (4.3) | 0.74% | — | MoodleFedoraproject Fedora | 23/3/2023 | 17/6/2026 | Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access. | |
| Modificada | Crítica (9.8) | 1.2% | — | MoodleFedoraproject Fedora | 23/3/2023 | 17/6/2026 | The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS). | |
| Modificada | Baja (3.3) | 0.23% | — | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 23/3/2023 | 17/6/2026 | A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak. | |
| Modificada | Media (6.5) | 1.8% | — | HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+5 | 23/3/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability. | |
| Modificada | Media (6.3) | 0.31% | — | QemuFedoraproject Fedora | 23/3/2023 | 17/6/2026 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU. | |
| Modificada | Media (5.5) | 0.86% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 23/3/2023 | 17/6/2026 | A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When… | |
| Modificada | Media (6.1) | 0.73% | — | CkeditorFedoraproject Fedora | 22/3/2023 | 17/6/2026 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special conditions: using one of the affected packages on a web page with… | |
| Modificada | Alta (8.8) | 1.3% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.85% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.3% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 3.2% | — | Google ChromeFedoraproject FedoraChromium | 21/3/2023 | 17/6/2026 | Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.82% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.8) | 1.1% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.77% | — | Google ChromeFedoraproject Fedora | 21/3/2023 | 17/6/2026 | Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (6.5) | 0.27% | — | XENDebian LinuxFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would… | |
| Modificada | Alta (8.6) | 1.2% | — | XENDebian LinuxFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would… | |
| Modificada | Alta (7.8) | 0.27% | — | XENDebian LinuxFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data… | |
| Modificada | Media (5.5) | 0.27% | — | XENFedoraproject Fedora | 21/3/2023 | 17/6/2026 | x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative… | |
| Modificada | Media (5.5) | 0.43% | — | VIMFedoraproject Fedora | 7/3/2023 | 17/6/2026 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392. | |
| Modificada | Alta (8.6) | 1.2% | — | C-ares Project C-aresRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 6/3/2023 | 17/6/2026 | A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity. | |
| Modificada | Media (5.9) | 0.76% | — | SambaFedoraproject Fedora | 6/3/2023 | 17/6/2026 | Se ha encontrado un fallo en samba. Una condición de ejecución en el código de bloqueo de contraseñas puede conllevar el riesgo de que los ataques de fuerza bruta tengan éxito si se cumplen unas condiciones especiales. |