Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

6097 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.1%—LibsshFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,`…
ModificadaMedia (5.5)0.39%—AvahiFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
ModificadaMedia (6.5)1.3%—LibsshFedoraproject FedoraDebian LinuxRedhat Enterprise Linux26/5/202317/6/2026
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
ModificadaMedia (6.5)0.43%—Redhat Build OF QuarkusRedhat Jboss A-mqRedhat KeycloakRedhat Migration Toolkit FOR Runtimes+126/5/202317/6/2026
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the…
ModificadaMedia (6.4)0.35%—Linux KernelRedhat Enterprise Linux18/5/202317/6/2026
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.
ModificadaCrítica (9.8)0.97%—Clusterlabs PCSRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUS17/5/202317/6/2026
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was…
ModificadaAlta (7.5)1.6%—LibreswanRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+117/5/202317/6/2026
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder…
ModificadaMedia (5.5)0.43%—LibtiffFedoraproject FedoraRedhat Enterprise Linux17/5/202317/6/2026
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
ModificadaAlta (7.8)0.46%—GNU EmacsRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+117/5/202317/6/2026
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat…
ModificadaAlta (8.8)0.93%—Webkitgtk Webkit2gtk3Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+117/5/202317/6/2026
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205…
ModificadaMedia (5.5)0.25%—Redhat LibvirtFedoraproject FedoraRedhat Enterprise Linux15/5/202317/6/2026
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
AnalizadaMedia (6.5)1.3%—LibrawFedoraproject FedoraRedhat Enterprise Linux15/5/202317/6/2026
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
ModificadaMedia (6.5)1.2%—Redhat Openstack12/5/202317/6/2026
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
ModificadaMedia (6.5)0.88%—QTRedhat Enterprise Linux10/5/202317/6/2026
In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
ModificadaAlta (7.5)6.1%—Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux9/5/202317/6/2026
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the…
ModificadaMedia (6.7)0.24%—Linux KernelRedhat Enterprise Linux8/5/202317/6/2026
A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors.
ModificadaAlta (7.8)13%💥 PoCLinux KernelRedhat Enterprise LinuxNetapp HCI Baseboard Management Controller8/5/202317/6/2026
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
ModificadaAlta (7.8)0.37%—Lfprojects ApptainerSylabs SingularityRedhat Enterprise Linux25/4/202317/6/2026
Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. That includes Red Hat Enterprise Linux 7, Debian…
ModificadaMedia (4.4)0.34%—Linux KernelRedhat Enterprise Linux24/4/202317/6/2026
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
ModificadaMedia (6.7)0.24%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux20/4/202317/6/2026
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash…
ModificadaMedia (5.5)0.22%—Linux KernelRedhat Enterprise Linux19/4/202317/6/2026
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.
ModificadaMedia (5.5)0.19%—Linux KernelRedhat Enterprise Linux19/4/202317/6/2026
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.
ModificadaAlta (8.2)1.2%—Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+210/4/202317/6/2026
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,…
ModificadaAlta (7.1)0.25%—Linux KernelRedhat Enterprise Linux29/3/202317/6/2026
A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.
ModificadaAlta (7.8)0.22%—Redhat Device-mapper-multipathRedhat Enterprise Linux29/3/202317/6/2026
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue…