Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
4419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.92% | — | Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+12 | 16/1/2026 | 17/6/2026 | Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in… | |
| Analizada | Crítica (9.3) | 0.84% | — | Canon Lbp1238 II FirmwareCanon Lbp632cdw FirmwareCanon Lbp633cdw FirmwareCanon Lbp236dw Firmware+12 | 16/1/2026 | 17/6/2026 | Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold… | |
| Analizada | Crítica (9.3) | 0.92% | — | Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+12 | 16/1/2026 | 17/6/2026 | Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold… | |
| Analizada | Crítica (9.3) | 0.92% | — | Canon Lbp1238 II FirmwareCanon Lbp632cdw FirmwareCanon Lbp633cdw FirmwareCanon Lbp236dw Firmware+12 | 16/1/2026 | 17/6/2026 | Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold… | |
| Analizada | Baja (1.9) | 0.18% | — | Canonical Apport | 10/12/2025 | 17/6/2026 | It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups. | |
| Analizada | Media (6.5) | 0.27% | — | Canonical Maas | 3/12/2025 | 17/6/2026 | An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an… | |
| Aplazada | Media (6) | 0.22% | — | Nanomq NanonnAIEmqx NanomqAI | 25/11/2025 | 17/6/2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). The vulnerability is due to… | |
| Analizada | Alta (7.1) | 0.58% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links. | |
| Analizada | Media (4.8) | 0.32% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths. | |
| Analizada | Media (6.9) | 0.39% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses. | |
| Analizada | Media (6.9) | 0.34% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints. | |
| Analizada | Alta (7.4) | 0.21% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format | |
| Analizada | Media (5.1) | 0.35% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line. | |
| Analizada | Alta (7.1) | 0.37% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine. | |
| Analizada | Alta (7.5) | 0.13% | — | Canonical LXD | 2/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication. | |
| Aplazada | Media (6.9) | 0.38% | — | Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+9 | 29/9/2025 | 17/6/2026 | Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / Generic FAX Driver / LIPS4… | |
| Aplazada | Media (5.9) | 0.36% | — | Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+9 | 29/9/2025 | 17/6/2026 | Out-of-bounds write vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / Generic FAX Driver / LIPS4… | |
| Aplazada | Media (5.9) | 0.31% | — | Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+9 | 29/9/2025 | 17/6/2026 | Out-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / Generic FAX Driver / LIPS4… | |
| Aplazada | Alta (8.8) | 0.36% | — | Touch Lebanon Mobile APPAI | 20/8/2025 | 17/6/2026 | A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate… | |
| Analizada | Crítica (9.8) | 0.36% | — | Canonical Metal AS A Service | 21/7/2025 | 17/6/2026 | Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps. | |
| Analizada | Alta (7.8) | 0.16% | — | Canonical Multipass | 12/7/2025 | 17/6/2026 | In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup. | |
| Analizada | Alta (8.8) | 0.65% | — | Canonical Juju | 8/7/2025 | 17/6/2026 | In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines,… | |
| Analizada | Media (6.5) | 0.72% | — | Canonical Juju | 8/7/2025 | 17/6/2026 | The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm. | |
| Analizada | Media (6.5) | 0.35% | — | Canonical Juju | 8/7/2025 | 17/6/2026 | The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information. | |
| Analizada | Media (6.5) | 0.16% | — | Canonical Juju/utils | 1/7/2025 | 17/6/2026 | Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it. |