Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 4.3% | — | BluezDebian LinuxOpensuse Leap | 15/10/2020 | 17/6/2026 | In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event. | |
| Modificada | Crítica (9.3) | 2.0% | — | Sylabs SingularityOpensuse Backports SLEOpensuse Leap | 14/10/2020 | 17/6/2026 | Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the extraction with a crafted squashfs… | |
| Modificada | Alta (7.5) | 2.4% | — | Linux KernelDebian LinuxNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+3 | 13/10/2020 | 17/6/2026 | A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this… | |
| Modificada | Crítica (9.8) | 67% | 💥 Exploit | PhpmyadminOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 10/10/2020 | 17/6/2026 | An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query. | |
| Modificada | Media (6.1) | 1.9% | — | PhpmyadminOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 10/10/2020 | 17/6/2026 | phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. | |
| Modificada | Media (5.5) | 0.55% | — | KdeconnectOpensuse Backports SLEOpensuse Leap | 7/10/2020 | 17/6/2026 | In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack. | |
| Modificada | Crítica (9.8) | 9.2% | 💥 PoC | ZabbixOpensuse Backports SLEOpensuse LeapDebian Linux | 7/10/2020 | 17/6/2026 | Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. | |
| Modificada | Media (6.6) | 2.7% | — | Spice Project SpiceRedhat OpenstackCanonical Ubuntu LinuxDebian Linux+6 | 7/10/2020 | 17/6/2026 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when… | |
| Modificada | Alta (7.5) | 4.0% | — | WiresharkFedoraproject FedoraOpensuse LeapOracle ZFS Storage Appliance KIT | 6/10/2020 | 17/6/2026 | In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs. | |
| Modificada | Alta (7.5) | 4.9% | — | WiresharkFedoraproject FedoraOpensuse LeapDebian Linux+1 | 6/10/2020 | 17/6/2026 | In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts. | |
| Modificada | Alta (7.5) | 2.4% | — | WiresharkFedoraproject FedoraOpensuse LeapDebian Linux+1 | 6/10/2020 | 17/6/2026 | In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum. | |
| Modificada | Alta (7.2) | 3.3% | — | Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+2 | 6/10/2020 | 17/6/2026 | A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data… | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+1 | 6/10/2020 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block… | |
| Modificada | Media (6.7) | 0.53% | 💥 PoC | Redhat LibvirtOpensuse Leap | 6/10/2020 | 17/6/2026 | A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL… | |
| Modificada | Media (5.3) | 1.9% | — | Nextcloud Preferred ProvidersOpensuse Backports SLEOpensuse Leap | 5/10/2020 | 17/6/2026 | A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times. | |
| Modificada | Media (5.3) | 5.0% | — | PHPFedoraproject FedoraDebian LinuxOpensuse Leap+3 | 2/10/2020 | 17/6/2026 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge… | |
| Modificada | Media (6.5) | 2.1% | — | PHPFedoraproject FedoraDebian LinuxOpensuse Leap+4 | 2/10/2020 | 17/6/2026 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data. | |
| Modificada | Alta (8.8) | 1.9% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdOpensuse Leap+1 | 1/10/2020 | 17/6/2026 | When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules. This vulnerability affects Firefox < 81, Thunderbird <… | |
| Modificada | Media (6.1) | 1.7% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+1 | 1/10/2020 | 17/6/2026 | By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird… | |
| Modificada | Media (6.1) | 1.6% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+1 | 1/10/2020 | 17/6/2026 | Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3. | |
| Modificada | Alta (8.8) | 2.0% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+1 | 1/10/2020 | 17/6/2026 | Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and… | |
| Modificada | Alta (8.8) | 0.43% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to any address in the vhost_crypto application. The highest threat from this vulnerability is to data… | |
| Modificada | Baja (3.3) | 0.40% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used… | |
| Modificada | Alta (7.1) | 0.41% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual… | |
| Modificada | Alta (7.8) | 0.40% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |