Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)1.2%💥 PoCLinux KernelFedoraproject FedoraRedhat Build OF QuarkusRedhat Developer Tools+2618/3/202226/8/2026
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
ModificadaMedia (6.5)0.37%—QemuFedoraproject FedoraRedhat Openstack PlatformRedhat Enterprise Linux+416/3/202217/6/2026
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The…
AnalizadaAlta (7.8)93%⚠ Explotación activa💥 ExploitLinux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2510/3/202217/6/2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read…
ModificadaAlta (7.8)0.34%—Linux KernelFedoraproject FedoraDebian LinuxRedhat Virtualization Host+1910/3/202217/6/2026
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
ModificadaMedia (6.5)4.7%—PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+1610/3/202217/6/2026
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to…
ModificadaAlta (7.5)12%—PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+134/3/202217/6/2026
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
ModificadaAlta (8.8)0.66%💥 PoCLinux KernelFedoraproject FedoraRedhat Software CollectionsRedhat Openstack+224/3/202217/6/2026
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable…
ModificadaMedia (5.5)0.53%—Linux KernelFedoraproject FedoraDebian LinuxRedhat Build OF Quarkus+194/3/202217/6/2026
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.
ModificadaAlta (8.1)1.9%—PostgresqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+24/3/202217/6/2026
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
AnalizadaAlta (7.8)5.5%⚠ Explotación activa💥 ExploitNetapp H300s FirmwareNetapp H410c FirmwareNetapp H410s FirmwareNetapp H500s Firmware+233/3/202217/6/2026
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
ModificadaMedia (5.5)0.39%—Redhat Ansible Automation Platform Early AccessRedhat Ansible EngineRedhat OpenstackRedhat Virtualization+53/3/202217/6/2026
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
ModificadaAlta (7)0.43%—Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+283/3/202217/6/2026
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
ModificadaMedia (5.5)0.33%—Buildah Project BuildahRedhat Enterprise LinuxRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR Power Little Endian3/3/202217/6/2026
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may…
ModificadaMedia (6.5)1.4%—PostgresqlRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux FOR IBM Z Systems+32/3/202217/6/2026
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known…
ModificadaAlta (8.8)74%💥 PoCSambaDebian LinuxCanonical Ubuntu LinuxSynology Diskstation Manager+1921/2/202217/6/2026
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially…
ModificadaAlta (7.5)2.0%—Port389 389-ds-baseRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR Power BIG Endian+418/2/202217/6/2026
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
ModificadaMedia (6.5)0.34%—QemuRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+618/2/202217/6/2026
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
ModificadaAlta (7.2)1.7%—SambaDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1318/2/202217/6/2026
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total…
ModificadaAlta (8.1)1.6%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2118/2/202217/6/2026
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
ModificadaMedia (5.9)1.8%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2018/2/202217/6/2026
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
ModificadaAlta (7.8)0.19%—DogtagpkiFedoraproject FedoraOracle LinuxRedhat Enterprise Linux+816/2/202217/6/2026
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this…
AnalizadaAlta (7.8)94%⚠ Explotación activa💥 ExploitPolkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2628/1/202215/8/2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends…
ModificadaMedia (5.6)2.8%—C-ares Project C-aresFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Computer Node+1323/11/202117/6/2026
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system…
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaMedia (6.5)1.2%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+927/5/202117/6/2026
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.