Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.25% | — | Teradata DatabaseAISuse Linux Enterprise ServerAI | 8/1/2025 | 17/6/2026 | Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts,… | |
| Aplazada | Crítica (9.8) | 1.9% | 💥 PoC | Saiful.total Wp-nssuser-registerAI | 16/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.6) | 0.28% | — | Suse ManagerAI | 28/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization credentials sub page. This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE… | |
| Aplazada | Media (4.6) | 0.28% | — | Suse ManagerAISuse Spacewalk-webAI | 28/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Container… | |
| Aplazada | Media (5.7) | 0.17% | — | Suse UyuniAI | 28/11/2024 | 17/6/2026 | The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users. | |
| Analizada | Media (5.3) | 0.33% | — | Opensuse Mirrorcache | 13/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters. This issue affects MirrorCache before 1.083. | |
| Modificada | Alta (7.8) | 0.39% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.29% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space. | |
| Modificada | Alta (7.8) | 0.39% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution. | |
| Modificada | Alta (7.8) | 0.36% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution. | |
| Aplazada | Media (5.5) | 0.21% | — | Opensuse OSCAI | 16/10/2024 | 17/6/2026 | Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim | |
| Analizada | Alta (8.4) | 2.0% | — | Suse Rancher | 16/10/2024 | 17/6/2026 | A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have it enabled and have… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Aplazada | Alta (8.8) | 1.0% | — | CockpitAIOpensuse PCPAI | 28/3/2024 | 17/6/2026 | A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The… | |
| Modificada | Media (5.5) | 0.29% | — | Relax-and-recoverSuse Linux EnterpriseRedhat Enterprise LinuxFedoraproject Fedora | 12/1/2024 | 17/6/2026 | Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root. | |
| Modificada | Alta (8.8) | 1.0% | — | Suse Rancher | 12/12/2023 | 17/6/2026 | In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project. | |
| Modificada | Crítica (9.4) | 0.46% | — | Suse Manager Server | 20/9/2023 | 17/6/2026 | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE. | |
| Modificada | Alta (7.8) | 0.30% | — | Opensuse LeapSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Desktop | 19/9/2023 | 17/6/2026 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1;… | |
| Modificada | Alta (7.5) | 0.70% | — | Suse Rancher Rke2 | 19/9/2023 | 17/6/2026 | A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects RKE2: from 1.24.0 before 1.24.17+rke2r1, from v1.25.0 before v1.25.13+rke2r1, from v1.26.0 before… | |
| Modificada | Alta (7.8) | 0.31% | — | Opensuse Welcome | 19/9/2023 | 17/6/2026 | A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a. | |
| Modificada | Alta (7.8) | 0.21% | — | Opensuse Tumbleweed | 7/7/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed. | |
| Modificada | Alta (8.8) | 0.45% | — | Suse Rancher | 1/6/2023 | 17/6/2026 | A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower… | |
| Modificada | Alta (8) | 0.71% | — | Suse Rancher | 1/6/2023 | 17/6/2026 | An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being preserved. When this operation was followed-up… | |
| Modificada | Alta (8.4) | 0.71% | — | Suse Rancher | 1/6/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform… | |
| Modificada | Media (6.5) | 0.57% | — | Opensuse Libeconf | 1/6/2023 | 17/6/2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuration files This issue affects libeconf: before 0.5.2. |