Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 3.3% | — | NTPNetapp Cloud BackupNetapp Clustered Data OntapNetapp Data Ontap+21 | 4/6/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query… | |
| Modificada | Media (6.5) | 5.2% | — | Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+20 | 18/5/2020 | 17/6/2026 | gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4. | |
| Modificada | Media (5.3) | 0.40% | — | Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+21 | 15/5/2020 | 17/6/2026 | The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+20 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails. | |
| Modificada | Media (6.7) | 0.59% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040. | |
| Modificada | Media (5.5) | 0.65% | — | Linux KernelDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8. | |
| Modificada | Media (6.4) | 0.36% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux+18 | 8/5/2020 | 17/6/2026 | There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it… | |
| Modificada | Alta (7.8) | 0.45% | — | Linux KernelOpensuse LeapDebian LinuxNetapp Active IQ Unified Manager+18 | 5/5/2020 | 17/6/2026 | An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea. | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (7) | 0.40% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+19 | 29/4/2020 | 17/6/2026 | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur. | |
| Modificada | Alta (7.5) | 4.4% | — | OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+14 | 28/4/2020 | 17/6/2026 | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). | |
| Modificada | Media (5.5) | 0.45% | — | Canonical Ubuntu LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management NodeNetapp Steelstore Cloud Integrated Storage+28 | 10/4/2020 | 17/6/2026 | The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this… | |
| Modificada | Alta (7.8) | 6.0% | 💥 PoC | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+23 | 2/4/2020 | 17/6/2026 | In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was… | |
| Modificada | Alta (7.5) | 7.8% | — | Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+20 | 21/1/2020 | 17/6/2026 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. | |
| Modificada | Alta (7.5) | 3.1% | — | Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+20 | 21/1/2020 | 17/6/2026 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. | |
| Modificada | Alta (7.5) | 3.5% | — | Linux KernelOpensuse LeapNetapp AFF A700s FirmwareNetapp H300s Firmware+13 | 30/9/2019 | 17/6/2026 | In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d. | |
| Modificada | Alta (7.8) | 0.91% | — | Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Compute Node EUS+35 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.87% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+30 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.76% | — | Linux KernelRedhat Virtualization HostRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+24 | 19/9/2019 | 17/6/2026 | An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be… | |
| Modificada | Alta (7.8) | 0.62% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+30 | 17/9/2019 | 17/6/2026 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could… | |
| Modificada | Alta (7.5) | 3.9% | — | Linux KernelCanonical Ubuntu LinuxNetapp Data Availability ServicesNetapp HCI Management Node+14 | 25/8/2019 | 17/6/2026 | An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack… | |
| Modificada | Alta (7.5) | 2.7% | — | Linux KernelRedhat Developer ToolsRedhat MRG RealtimeRedhat Enterprise Linux+16 | 30/7/2019 | 17/6/2026 | A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any… |