Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
4419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.61% | — | Canonical LXD | 9/4/2026 | 17/6/2026 | Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project restriction. A remote attacker with can_edit… | |
| Analizada | Alta (7.1) | 0.23% | — | Canonical Juju | 3/4/2026 | 24/7/2026 | Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju controller can modify the… | |
| Analizada | Media (6.9) | 0.36% | — | Canonical Juju | 3/4/2026 | 24/7/2026 | Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible that a compromised workload machine under a Juju controller can read… | |
| Analizada | Crítica (10) | 0.41% | — | Canonical Juju | 1/4/2026 | 17/6/2026 | A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node… | |
| Analizada | Media (5.1) | 0.19% | — | Anonproxyserver Anon Proxy Server | 31/3/2026 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions… | |
| Analizada | Media (5.1) | 0.19% | — | Anonproxyserver Anon Proxy Server | 31/3/2026 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions… | |
| Analizada | Media (5.1) | 0.19% | — | Anonproxyserver Anon Proxy Server | 31/3/2026 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions… | |
| Analizada | Media (6.6) | 0.38% | — | Canonical Juju | 18/3/2026 | 17/6/2026 | In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious grantee which can request secrets to predict past secrets granted by the same secret owner to… | |
| Analizada | Alta (8.8) | 0.44% | — | Canonical Juju | 18/3/2026 | 17/6/2026 | In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated… | |
| Analizada | Media (6.5) | 0.28% | — | Canonical Juju | 18/3/2026 | 17/6/2026 | An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that… | |
| Analizada | Media (5.3) | 0.27% | — | Canonical Juju | 18/3/2026 | 17/6/2026 | A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim… | |
| Analizada | Alta (7.8) | 0.18% | 💥 PoC | Canonical Ubuntu Linux | 17/3/2026 | 17/6/2026 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS. | |
| Modificada | Media (6.9) | 1.3% | — | Canonical Ubuntu LinuxOpenbsd OpensshDebian LinuxRedhat Enterprise Linux | 12/3/2026 | 15/7/2026 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an… | |
| Analizada | Crítica (9.4) | 0.86% | — | Canonical LXD | 12/3/2026 | 18/9/2026 | An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions… | |
| Analizada | Baja (2.1) | 0.22% | — | Canonical LXD | 3/3/2026 | 17/6/2026 | Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server. | |
| Aplazada | Alta (8) | 0.29% | — | Dalibo Postgresql AnonymizerAI | 11/2/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then called, the malicious code is executed with superuser privileges. This privilege elevation can… | |
| Aplazada | Alta (8) | 0.44% | — | Dalibo Postgresql AnonymizerAI | 11/2/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This operator will later be executed with superuser privileges when the extension is created. The risk is higher with PostgreSQL… | |
| Aplazada | Baja (2.1) | 0.14% | — | Canonical JujuAI | 28/1/2026 | 17/6/2026 | Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions.… | |
| Aplazada | Alta (8.8) | 0.47% | — | Aivahthemes AnonaAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0. | |
| Aplazada | Alta (7.5) | 0.50% | — | Aivaththemes AnonaAI | 22/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0. | |
| Aplazada | Alta (8.6) | 0.52% | — | Aivahthemes AnonaAI | 22/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Cleversoft AnonAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10. | |
| Analizada | Crítica (9.3) | 0.99% | — | Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+12 | 16/1/2026 | 17/6/2026 | Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in… | |
| Analizada | Crítica (9.3) | 0.92% | — | Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+12 | 16/1/2026 | 17/6/2026 | Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in… | |
| Analizada | Crítica (9.3) | 0.92% | — | Canon Mf656cdw FirmwareCanon Mf653cdw FirmwareCanon Mf652cw FirmwareCanon Mf1238 II Firmware+12 | 16/1/2026 | 17/6/2026 | Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier… |