Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PUT request. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request. | |
| Analizada | Alta (7.8) | 0.17% | — | Freebsd | 26/8/2026 | 10/9/2026 | mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root. | |
| Analizada | Alta (8.8) | 0.60% | — | Freebsd | 26/8/2026 | 10/9/2026 | LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root. | |
| Analizada | Alta (8.8) | 0.60% | — | Freebsd | 26/8/2026 | 10/9/2026 | mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root. | |
| Analizada | Alta (7.8) | 0.12% | — | Freebsd | 26/8/2026 | 24/9/2026 | The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page size had already been configured without holding the rangelock. Two… | |
| Analizada | Alta (7) | 0.10% | — | Freebsd | 26/8/2026 | 24/9/2026 | The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can… | |
| Analizada | Alta (8.1) | 0.35% | — | Freebsd | 26/8/2026 | 24/9/2026 | In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel… | |
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 26/8/2026 | 24/9/2026 | The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility. On a system… | |
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 26/8/2026 | 24/9/2026 | The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate… | |
| Analizada | Alta (7.8) | 0.14% | — | Freebsd | 26/8/2026 | 24/9/2026 | When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process… | |
| Aplazada | Alta (8.5) | 0.43% | — | RustdeskAIFreerdpAI | 24/8/2026 | 23/9/2026 | RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a… | |
| Analizada | Alta (8.2) | 0.18% | — | Amazon Freertos | 21/8/2026 | 25/8/2026 | Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Alta (8.3) | 0.16% | — | Amazon Freertos | 21/8/2026 | 25/8/2026 | Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Alta (8.3) | 0.16% | — | Amazon Freertos | 21/8/2026 | 27/8/2026 | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Analizada | Crítica (9.3) | 0.17% | — | Amazon Freertos | 21/8/2026 | 27/8/2026 | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later. | |
| Aplazada | Media (6.8) | 0.39% | — | Linkwhisper Link Whisper FreeAI | 21/8/2026 | 26/8/2026 | The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. | |
| Aplazada | Baja (3.7) | 0.31% | — | Freedom OF THE Press Foundation Securedrop ClientAIFreedom OF THE Press Foundation Securedrop ServerAIFreedom OF THE Press Foundation Securedrop-proxyAI | 20/8/2026 | 18/9/2026 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has… | |
| Pendiente de análisis | Media (6.5) | 0.52% | — | Redhat IPAAIRedhat FreeipaAI | 20/8/2026 | 20/8/2026 | A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation,… | |
| Analizada | Media (6.5) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 20/8/2026 | 24/8/2026 | A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service,… |