Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.5) | 0.47% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+9 | 6/7/2022 | 17/6/2026 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman… | |
| Modificada | Media (4.5) | 0.46% | — | GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+10 | 6/7/2022 | 17/6/2026 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform… | |
| Modificada | Alta (8.8) | 4.2% | 💥 PoC | Podman Project PodmanPsgo Project PsgoRedhat Developer ToolsRedhat Enterprise Linux Server Update Services FOR SAP Solutions+12 | 29/4/2022 | 17/6/2026 | A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem,… | |
| Modificada | Alta (7.5) | 1.4% | — | Podman Project PodmanRedhat Developer ToolsRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 4/4/2022 | 17/6/2026 | A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with… | |
| Modificada | Alta (8.8) | 68% | 💥 PoC | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+26 | 25/3/2022 | 17/6/2026 | A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access… | |
| Analizada | Alta (7.8) | 0.38% | — | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+34 | 25/3/2022 | 5/8/2026 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system. | |
| Analizada | Alta (7.8) | 1.2% | 💥 PoC | Linux KernelFedoraproject FedoraRedhat Build OF QuarkusRedhat Developer Tools+26 | 18/3/2022 | 26/8/2026 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation. | |
| Analizada | Alta (7.8) | 93% | ⚠ Explotación activa💥 Exploit | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+25 | 10/3/2022 | 17/6/2026 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read… | |
| Modificada | Alta (7.8) | 0.34% | — | Linux KernelFedoraproject FedoraDebian LinuxRedhat Virtualization Host+19 | 10/3/2022 | 17/6/2026 | A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4. | |
| Modificada | Media (6.5) | 4.7% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+16 | 10/3/2022 | 17/6/2026 | There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to… | |
| Modificada | Alta (8.8) | 0.66% | 💥 PoC | Linux KernelFedoraproject FedoraRedhat Software CollectionsRedhat Openstack+22 | 4/3/2022 | 17/6/2026 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable… | |
| Modificada | Media (5.5) | 0.53% | — | Linux KernelFedoraproject FedoraDebian LinuxRedhat Build OF Quarkus+19 | 4/3/2022 | 17/6/2026 | A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808. | |
| Analizada | Alta (7.8) | 5.5% | ⚠ Explotación activa💥 Exploit | Netapp H300s FirmwareNetapp H410c FirmwareNetapp H410s FirmwareNetapp H500s Firmware+23 | 3/3/2022 | 17/6/2026 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly. | |
| Modificada | Alta (7) | 0.43% | — | Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+28 | 3/3/2022 | 17/6/2026 | .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root. | |
| Modificada | Alta (8.8) | 74% | 💥 PoC | SambaDebian LinuxCanonical Ubuntu LinuxSynology Diskstation Manager+19 | 21/2/2022 | 17/6/2026 | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially… | |
| Modificada | Alta (7.5) | 2.0% | — | Port389 389-ds-baseRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR Power BIG Endian+4 | 18/2/2022 | 17/6/2026 | A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash. | |
| Modificada | Alta (7.2) | 1.7% | — | SambaDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+13 | 18/2/2022 | 17/6/2026 | A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total… | |
| Modificada | Alta (8.1) | 1.6% | — | SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+21 | 18/2/2022 | 17/6/2026 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. | |
| Modificada | Media (5.9) | 1.8% | — | SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+20 | 18/2/2022 | 17/6/2026 | A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. | |
| Modificada | Alta (7.8) | 0.19% | — | DogtagpkiFedoraproject FedoraOracle LinuxRedhat Enterprise Linux+8 | 16/2/2022 | 17/6/2026 | A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this… | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… | |
| Modificada | Alta (8.8) | 2.5% | — | Fedoraproject SssdRedhat VirtualizationRedhat Virtualization HostRedhat Enterprise Linux+4 | 23/12/2021 | 17/6/2026 | A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this… | |
| Modificada | Media (5.6) | 2.8% | — | C-ares Project C-aresFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Computer Node+13 | 23/11/2021 | 17/6/2026 | A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (6.5) | 1.2% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+9 | 27/5/2021 | 17/6/2026 | An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command. |