Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
4419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Aplazada | Media (4.6) | 0.18% | — | Canon EOS Webcam Utility PROAI | 26/6/2025 | 17/6/2026 | Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vulnerability. Exploitation of this vulnerability requires administrator access by a malicious user. An attacker could modify the directory, potentially resulting in code execution and ultimately… | |
| Analizada | Alta (8.8) | 0.27% | — | Canonical Cloud-init | 26/6/2025 | 17/6/2026 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration. | |
| Analizada | Media (5.3) | 0.14% | — | Canonical Cloud-init | 26/6/2025 | 17/6/2026 | cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands. | |
| Aplazada | Media (6.5) | 0.19% | — | Anonform AB Anon Form Embedded Secure FormAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anonform Ab ANON::form embedded secure form anonform-embedded-secure-form allows DOM-Based XSS.This issue affects ANON::form embedded secure form: from n/a through <= 1.7. | |
| Analizada | Alta (8.5) | 0.30% | — | Canonical Authd | 16/6/2025 | 17/6/2026 | A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session. | |
| Aplazada | Media (6.5) | 0.34% | — | Dalibo Postgresql AnonymizerAI | 4/6/2025 | 17/6/2026 | PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The… | |
| Modificada | Media (4.7) | 0.76% | 💥 PoC | Canonical ApportCanonical Ubuntu Linux | 30/5/2025 | 17/6/2026 | Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before… | |
| Analizada | Crítica (9.8) | 0.88% | — | Canon Satera Mf656cdw FirmwareCanon Satera Mf654cdw FirmwareCanon Satera Mf551dw FirmwareCanon Satera Mf457dw Firmware+33 | 26/5/2025 | 17/6/2026 | Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw… | |
| Analizada | Media (4.9) | 0.23% | — | Gnome Control CenterCanonical Ubuntu Linux | 15/4/2025 | 17/6/2026 | In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user. | |
| Aplazada | Media (5) | 0.17% | — | Canonical Charmed Mysql K8S OperatorAI | 9/4/2025 | 17/6/2026 | Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator calls mysql-shell application rely on writing to a temporary script file containing… | |
| Aplazada | Alta (7.1) | 0.38% | — | Hivedigital Canonical AttachmentsAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments canonical-attachments allows Reflected XSS.This issue affects Canonical Attachments: from n/a through <= 1.8. | |
| Aplazada | Alta (8.2) | 0.58% | — | Canonical Get-workflow-version-actionAI | 2/4/2025 | 17/6/2026 | canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the GITHUB_TOKEN. If the full token is included in the exception output, GitHub… | |
| Analizada | Alta (7.5) | 0.43% | — | Canonical Linux-bluefield | 31/3/2025 | 17/6/2026 | Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package. | |
| Aplazada | Crítica (9.4) | 0.81% | — | Canon Generic Plus Pcl6 Printer DriverAICanon Generic Plus UFR II Printer DriverAICanon Generic Plus Lips4 Printer DriverAICanon Generic Plus Lipslx Printer DriverAI+10 | 31/3/2025 | 17/6/2026 | Out-of-bounds vulnerability in EMF Recode processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver / Generic FAX Printer Driver / UFRII LT Printer Driver / CARPS2 Printer Driver / PDF… | |
| Analizada | Media (5.5) | 0.14% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 25/3/2025 | 17/6/2026 | accountsservice no longer drops permissions when writting .pam_environment | |
| Modificada | Media (5.9) | 41% | 💥 PoC | Openbsd OpensshCanonical Ubuntu LinuxDebian Linux | 28/2/2025 | 30/6/2026 | A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled… | |
| Aplazada | Alta (7.1) | 0.31% | — | Fabio Zuanon ADD Custom Content After PostAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Zuanon Add custom content after post add-custom-content-after-post allows Reflected XSS.This issue affects Add custom content after post: from n/a through <= 1.0. | |
| Analizada | Media (4.9) | 0.63% | — | Canonical Juju | 31/1/2025 | 17/6/2026 | An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem. | |
| Analizada | Crítica (9.8) | 0.74% | — | Gnome-remote-desktopCanonical Ubuntu Linux | 31/1/2025 | 17/6/2026 | Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. | |
| Analizada | Baja (3.1) | 0.34% | — | Canonical Apport | 31/1/2025 | 17/6/2026 | gdbus setgid privilege escalation | |
| Analizada | Alta (7.5) | 0.40% | — | Canonical Apport | 31/1/2025 | 17/6/2026 | Users can consume unlimited disk space in /var/crash | |
| Analizada | Crítica (9.8) | 1.2% | — | Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+18 | 28/1/2025 | 17/6/2026 | Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan.… | |
| Analizada | Crítica (9.8) | 1.2% | — | Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+18 | 28/1/2025 | 17/6/2026 | Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan.… | |
| Analizada | Crítica (9.8) | 1.2% | — | Canon Mf455dw FirmwareCanon Mf453dw FirmwareCanon Mf452dw FirmwareCanon Mf451dw Firmware+18 | 28/1/2025 | 17/6/2026 | Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan.… |