Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

4278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)41%💥 PoCOpenbsd OpensshCanonical Ubuntu LinuxDebian Linux28/2/202530/6/2026
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled…
AnalizadaMedia (4.9)0.63%—Canonical Juju31/1/202517/6/2026
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
AnalizadaCrítica (9.8)0.74%—Gnome-remote-desktopCanonical Ubuntu Linux31/1/202517/6/2026
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
AnalizadaBaja (3.1)0.34%—Canonical Apport31/1/202517/6/2026
gdbus setgid privilege escalation
AnalizadaAlta (7.5)0.40%—Canonical Apport31/1/202517/6/2026
Users can consume unlimited disk space in /var/crash
AplazadaAlta (7.1)0.26%—Andon Ivanov OZ CanonicalAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andon Ivanov OZ Canonical oz-canonical allows Reflected XSS.This issue affects OZ Canonical: from n/a through <= 0.5.
AnalizadaBaja (3.8)0.16%—Canonical LXD6/12/202417/6/2026
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
AnalizadaBaja (3.8)0.16%—Canonical LXD6/12/202417/6/2026
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
AnalizadaMedia (6.4)0.28%—Canonical Authd10/10/202417/6/2026
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges.
AnalizadaAlta (8.8)0.58%—Canonical Authd3/10/202417/6/2026
Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
AnalizadaMedia (5.5)0.21%—Canonical Juju2/10/202417/6/2026
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
AnalizadaMedia (6.5)0.19%—Canonical Juju2/10/202417/6/2026
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
AnalizadaAlta (8)0.50%—Canonical Juju2/10/202417/6/2026
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same…
AnalizadaAlta (7.5)0.18%—Canonical Anbox Cloud18/9/202417/6/2026
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
ModificadaBaja (3.8)0.38%—Canonical Juju29/7/202417/6/2026
An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
ModificadaAlta (7.3)0.23%—Canonical Snapd25/7/202417/6/2026
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are…
ModificadaMedia (6.6)0.21%—Canonical Snapd25/7/202417/6/2026
In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Various file entries within the snap squashfs image (such as icons etc) are directly…
ModificadaAlta (8.2)0.31%—Canonical Snapd25/7/202417/6/2026
In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug…
AnalizadaAlta (7.8)0.26%—Canonical Ubuntu Desktop Provision23/7/202417/6/2026
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.
AplazadaMedia (4.4)0.20%—Canonical OPSAI22/7/202417/6/2026
The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing…
ModificadaAlta (8.1)100%💥 ExploitSonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+491/7/20241/9/2026
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
AnalizadaMedia (5.5)0.15%—Canonical Ubuntu Advantage Desktop Daemon27/6/202417/6/2026
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
AnalizadaAlta (8.8)0.26%—Canonical SnapdCanonical Ubuntu Linux21/6/202417/6/2026
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may…
ModificadaMedia (6.5)0.26%—Canonical Netplan7/6/202417/6/2026
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing