Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.10% | — | NetbsdAINetbsd OpencryptoAI | 18/5/2026 | 14/7/2026 | NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation… | |
| Modificada | Alta (8.1) | 1.8% | — | Freebsd | 30/4/2026 | 17/6/2026 | As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to overrun its buffer of… | |
| Analizada | Alta (7.8) | 0.16% | — | Freebsd | 30/4/2026 | 17/6/2026 | When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large file descriptors, e.g.,… | |
| Modificada | Alta (8.1) | 0.40% | — | Freebsd | 30/4/2026 | 17/6/2026 | When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to… | |
| Analizada | Alta (7.5) | 0.55% | — | Freebsd | 30/4/2026 | 17/6/2026 | Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured… | |
| Modificada | Alta (7.8) | 0.19% | 💥 PoC | Freebsd | 30/4/2026 | 17/6/2026 | An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges. | |
| Modificada | Alta (8.1) | 0.40% | — | Freebsd | 30/4/2026 | 17/6/2026 | The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8),… | |
| Analizada | Media (6.2) | 0.16% | — | Freebsd | 22/4/2026 | 17/6/2026 | In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3) interface. In particular, it would always treat… | |
| Analizada | Alta (8.4) | 0.18% | — | Freebsd | 22/4/2026 | 17/6/2026 | The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end up containing a pointer to freed memory. A malicious process can abuse the dangling pointer to… | |
| Analizada | Media (4.3) | 0.25% | 💥 PoC | Openbsd | 21/4/2026 | 17/6/2026 | In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 - 2" expression with no preceding check for whether nd_opt_len is zero. | |
| Analizada | Media (6.1) | 0.30% | — | Libsdl SDL Image | 6/4/2026 | 24/7/2026 | SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range… | |
| Analizada | Alta (8.1) | 0.24% | 💥 PoC | Openbsd Openssh | 2/4/2026 | 24/7/2026 | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters. | |
| Analizada | Baja (2.5) | 0.23% | — | Openbsd Openssh | 2/4/2026 | 24/7/2026 | OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions. | |
| Analizada | Media (6.5) | 0.50% | — | Openbsd Openssh | 2/4/2026 | 24/7/2026 | OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms. | |
| Analizada | Alta (8.1) | 0.36% | — | Openbsd Openssh | 2/4/2026 | 24/7/2026 | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config. | |
| Modificada | Alta (8.1) | 0.63% | — | Openbsd Openssh | 2/4/2026 | 1/9/2026 | In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode). | |
| Analizada | Alta (7.5) | 0.42% | — | Freebsd | 1/4/2026 | 17/6/2026 | A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed using the address[/mask-bits] syntax were… | |
| Analizada | Alta (8.8) | 1.1% | 💥 PoC | Freebsd | 26/3/2026 | 17/6/2026 | Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to… | |
| Analizada | Alta (7.5) | 0.46% | — | Freebsd | 26/3/2026 | 17/6/2026 | On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an I/O queue with a bogus or stale CNTLID. An attacker with network access to the NVMe/TCP target can trigger an unauthenticated Denial of Service condition on the affected machine. | |
| Analizada | Alta (7.5) | 1.4% | — | Freebsd | 26/3/2026 | 17/6/2026 | When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is passed in. When no challenge ACK should be sent the function returns and leaks the mbuf. If an attacker is either on path with an established TCP connection, or can themselves establish a TCP… | |
| Modificada | Media (6.9) | 1.3% | — | Canonical Ubuntu LinuxOpenbsd OpensshDebian LinuxRedhat Enterprise Linux | 12/3/2026 | 15/7/2026 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an… | |
| Analizada | Alta (7.5) | 0.45% | — | Freebsd | 9/3/2026 | 17/6/2026 | The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr structures into a sockaddr_storage structure on the stack. It assumes that the source sockaddr length field had already been validated, but this is not necessarily the case, and it's possible for a… | |
| Analizada | Alta (7.5) | 0.37% | — | Freebsd | 9/3/2026 | 17/6/2026 | Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a certain number of leaked sockets is reached, blocklistd becomes unable to run the helper script: a child process is forked, but this child dereferences a null pointer and crashes before it is able to exec… | |
| Analizada | Alta (7.5) | 0.11% | — | Freebsd | 9/3/2026 | 17/6/2026 | If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has configured one. In this case, cooperating… | |
| Analizada | Alta (8.8) | 0.11% | — | Freebsd | 9/3/2026 | 17/6/2026 | By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to privilege checks. If a privileged user within a jail is able to nullfs-mount directories, a limitation of the kernel's path lookup logic allows that user to… |