Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 19/8/2026 | 1/9/2026 | The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation. A local user with the "receive" delegated ZFS permission can trigger kernel memory corruption via… | |
| Analizada | Alta (7.8) | 0.15% | — | Freebsd | 19/8/2026 | 1/9/2026 | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit size as the buffer limit when writing records. A local user with the "userused" delegated ZFS permission can trigger a kernel heap overflow via… | |
| Analizada | Alta (8.4) | 0.34% | — | Freebsd | 19/8/2026 | 1/9/2026 | Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug to access freed kernel memory. This can… | |
| Analizada | Alta (8.8) | 0.50% | — | Freebsd | 19/8/2026 | 1/9/2026 | Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object with the SF_NOCACHE flag, it freed the underlying pages after transmission even though existing mappings still referred to them. An unprivileged local user can abuse the bug to access freed kernel… | |
| Analizada | Baja (3.3) | 0.14% | — | Freebsd | 19/8/2026 | 1/9/2026 | When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actual result of the executed system call. As a result, committed audit records for system calls which returned an error do not reflect the true… | |
| Analizada | Alta (8.4) | 0.17% | — | Freebsd | 19/8/2026 | 1/9/2026 | The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, it verifies that the TCP stack had not been switched away, but did not reload its pointer to the stack's per-connection control block. If userspace switches stacks twice… | |
| Analizada | Alta (7.1) | 0.13% | — | Freebsd | 19/8/2026 | 1/9/2026 | The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag was silently dropped, so path resolution was not actually restricted. A process that uses AT_RESOLVE_BENEATH with unlinkat(2) or funlinkat(2) to… | |
| Analizada | Alta (8.8) | 0.42% | — | Freebsd | 19/8/2026 | 1/9/2026 | The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer, or whether the result fit back in the original packet. A host sending crafted RTSP traffic from inside a NAT gateway using libalias can overflow a stack buffer,… | |
| Analizada | Alta (8.8) | 0.47% | — | Freebsd | 19/8/2026 | 1/9/2026 | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the descriptor lookup failed, error-handling paths released the same reference a second time. An unprivileged local user can trigger a prison… | |
| Analizada | Alta (8.8) | 0.47% | — | Freebsd | 19/8/2026 | 1/9/2026 | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in the pager's page list. A subsequent page fault will cause the fault handler to re-insert the page into the object's list. This corrupts the list, and on object… | |
| Analizada | Alta (8.8) | 0.36% | — | Freebsd | 19/8/2026 | 1/9/2026 | During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running as the same user can access the target process's memory via procfs or linprocfs, because the kernel's debugging permission check still saw the original… | |
| Pendiente de análisis | Alta (7) | 0.20% | — | Freecadweb FreecadAI | 17/8/2026 | 9/9/2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd… | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Freecadweb FreecadAI | 17/8/2026 | 9/9/2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable code is in… | |
| Pendiente de análisis | Alta (7.8) | 0.22% | — | Freecadweb FreecadAI | 17/8/2026 | 9/9/2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary… | |
| Pendiente de análisis | Crítica (9.3) | 0.41% | — | FreepbxAIAsteriskAISocket.ioAI | 13/8/2026 | 10/9/2026 | FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth… | |
| Pendiente de análisis | Alta (8.6) | 0.51% | — | FreepbxAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the asterisk system user without reliably enforcing backup-only command and source… | |
| Pendiente de análisis | Crítica (9.3) | 1.7% | — | FreepbxAIFreepbx MissedcallAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a… | |
| Pendiente de análisis | Alta (7.6) | 0.64% | — | FreepbxAIAsteriskAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels,… | |
| Pendiente de análisis | Alta (8.6) | 0.60% | — | FreepbxAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or… | |
| Pendiente de análisis | Alta (7.5) | 0.77% | — | FreepbxAIAsteriskAI | 13/8/2026 | 18/9/2026 | FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames inside… | |
| Aplazada | Media (5.3) | 0.28% | — | Open5gsAIFreediameterAI | 12/8/2026 | 29/9/2026 | A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely. | |
| Pendiente de análisis | Media (6.1) | 0.12% | — | Freecadweb FreecadAI | 11/8/2026 | 9/9/2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml from a crafted .FCStd archive without disabling default external entity resolution or external DTD… | |
| Pendiente de análisis | Alta (7.8) | 0.24% | — | Freecadweb FreecadAI | 11/8/2026 | 9/9/2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document transient path without rejecting directory components, absolute paths, or… | |
| Pendiente de análisis | Alta (8.5) | 0.20% | — | Freecadweb FreecadAI | 11/8/2026 | 9/9/2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp passes the xDisplacementFormula, yDisplacementFormula, and zDisplacementFormula fields of a Fem::ConstraintDisplacement object through… | |
| Modificada | Alta (8.2) | 0.29% | — | Redhat Enterprise LinuxFreeipa | 11/8/2026 | 28/9/2026 | A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials,… |