Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3731 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 0.65% | — | Openbsd OpensshRedhat Hardened ImagesRedhat Enterprise Linux | 23/6/2026 | 24/9/2026 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving… | |
| Modificada | Media (6.5) | 0.51% | — | Openbsd OpensshRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 23/6/2026 | 7/10/2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters.… | |
| Analizada | Media (5.9) | 0.53% | — | Redhat Openshift Container PlatformRedhat Enterprise LinuxThekelleys Dnsmasq | 22/6/2026 | 31/8/2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may… | |
| Analizada | Media (4.8) | 0.36% | — | Redhat Enterprise LinuxGnome Libsoup | 22/6/2026 | 8/7/2026 | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206… | |
| Modificada | Media (5) | 0.35% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 18/6/2026 | 30/6/2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP… | |
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Analizada | Media (5.4) | 0.23% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 17/6/2026 | 28/6/2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace… | |
| Analizada | Alta (8.1) | 0.25% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the… | |
| Analizada | Media (6.1) | 0.16% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by… | |
| Analizada | Media (5.6) | 0.21% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 18/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a… | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject… | |
| Modificada | Alta (7.8) | 0.23% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the… | |
| Modificada | Media (6.9) | 1.0% | — | MariadbRedhat Enterprise Linux | 12/6/2026 | 17/9/2026 | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though… | |
| Modificada | Alta (7.5) | 0.99% | — | Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+2 | 10/6/2026 | 9/9/2026 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in… | |
| Analizada | Alta (8.7) | 0.73% | — | Image-sizeRedhat DiscoveryRedhat GatekeeperRedhat Trusted Artifact Signer+1 | 9/6/2026 | 24/7/2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by… | |
| Modificada | Media (4.9) | 0.29% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of… | |
| Modificada | Media (6.5) | 0.28% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication. | |
| Modificada | Alta (7.5) | 0.56% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 18/8/2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure. | |
| Modificada | Media (6.3) | 0.18% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior. | |
| Modificada | Media (6.5) | 0.16% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation. | |
| Modificada | Media (4.3) | 0.18% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. | |
| Modificada | Media (6.5) | 0.24% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 8/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or… | |
| Modificada | Alta (7.8) | 0.20% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 27/7/2026 | An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the… | |
| Modificada | Media (5.5) | 0.14% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure. | |
| Modificada | Media (5.5) | 0.13% | — | X.org X ServerX.org XwaylandRedhat Enterprise Linux | 5/6/2026 | 5/8/2026 | An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which… |