Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

4419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)55%⚠ Explotación activa💥 ExploitSudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+430/6/202517/6/2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
AplazadaMedia (4.6)0.18%—Canon EOS Webcam Utility PROAI26/6/202517/6/2026
Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vulnerability. Exploitation of this vulnerability requires administrator access by a malicious user. An attacker could modify the directory, potentially resulting in code execution and ultimately…
AnalizadaAlta (8.8)0.27%—Canonical Cloud-init26/6/202517/6/2026
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
AnalizadaMedia (5.3)0.14%—Canonical Cloud-init26/6/202517/6/2026
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
AplazadaMedia (6.5)0.19%—Anonform AB Anon Form Embedded Secure FormAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anonform Ab ANON::form embedded secure form anonform-embedded-secure-form allows DOM-Based XSS.This issue affects ANON::form embedded secure form: from n/a through <= 1.7.
AnalizadaAlta (8.5)0.30%—Canonical Authd16/6/202517/6/2026
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
AplazadaMedia (6.5)0.34%—Dalibo Postgresql AnonymizerAI4/6/202517/6/2026
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The…
ModificadaMedia (4.7)0.76%💥 PoCCanonical ApportCanonical Ubuntu Linux30/5/202517/6/2026
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before…
AnalizadaCrítica (9.8)0.88%—Canon Satera Mf656cdw FirmwareCanon Satera Mf654cdw FirmwareCanon Satera Mf551dw FirmwareCanon Satera Mf457dw Firmware+3326/5/202517/6/2026
Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw…
AnalizadaMedia (4.9)0.23%—Gnome Control CenterCanonical Ubuntu Linux15/4/202517/6/2026
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
AplazadaMedia (5)0.17%—Canonical Charmed Mysql K8S OperatorAI9/4/202517/6/2026
Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator calls mysql-shell application rely on writing to a temporary script file containing…
AplazadaAlta (7.1)0.38%—Hivedigital Canonical AttachmentsAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments canonical-attachments allows Reflected XSS.This issue affects Canonical Attachments: from n/a through <= 1.8.
AplazadaAlta (8.2)0.58%—Canonical Get-workflow-version-actionAI2/4/202517/6/2026
canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the GITHUB_TOKEN. If the full token is included in the exception output, GitHub…
AnalizadaAlta (7.5)0.43%—Canonical Linux-bluefield31/3/202517/6/2026
Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package.
AplazadaCrítica (9.4)0.81%—Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+1031/3/202517/6/2026
Out-of-bounds vulnerability in EMF Recode processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / Generic FAX Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / PDF…
AnalizadaMedia (5.5)0.14%—Canonical AccountsserviceCanonical Ubuntu Linux25/3/202517/6/2026
accountsservice no longer drops permissions when writting .pam_environment
ModificadaMedia (5.9)41%💥 PoCOpenbsd OpensshCanonical Ubuntu LinuxDebian Linux28/2/202530/6/2026
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled…
AplazadaAlta (7.1)0.31%—Fabio Zuanon ADD Custom Content After PostAI14/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Zuanon Add custom content after post add-custom-content-after-post allows Reflected XSS.This issue affects Add custom content after post: from n/a through <= 1.0.
AnalizadaMedia (4.9)0.63%—Canonical Juju31/1/202517/6/2026
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
AnalizadaCrítica (9.8)0.74%—Gnome-remote-desktopCanonical Ubuntu Linux31/1/202517/6/2026
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
AnalizadaBaja (3.1)0.34%—Canonical Apport31/1/202517/6/2026
gdbus setgid privilege escalation
AnalizadaAlta (7.5)0.40%—Canonical Apport31/1/202517/6/2026
Users can consume unlimited disk space in /var/crash
AnalizadaCrítica (9.8)1.2%—Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+1828/1/202517/6/2026
Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan.…
AnalizadaCrítica (9.8)1.2%—Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+1828/1/202517/6/2026
Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan.…
AnalizadaCrítica (9.8)1.2%—Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+1828/1/202517/6/2026
Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan.…