Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

10.167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.5%💥 PoCLinux KernelDebian LinuxFedoraproject FedoraNetapp H300s+45/7/202317/6/2026
Vulnerabilidad de Lectura/Escritura en nftables Fuera de los Límites del kernel de Linux; nft_byteorder administra incorrectamente los contenidos de registro de VM cuando CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red
ModificadaAlta (7.8)1.9%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux5/7/202317/6/2026
Vulnerabilidad de Escalada de Privilegios Locales de Use-After-Free de Linux nftables; 'nft_chain_lookup_byid()' no pudo comprobar si una cadena estaba activa y CAP_NET_ADMIN está en cualquier espacio de nombres de usuario o red
ModificadaAlta (8.8)0.75%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and…
ModificadaAlta (7.8)0.23%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaMedia (6.5)0.74%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaAlta (8.8)0.76%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaAlta (8.8)0.76%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux5/7/202317/6/2026
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
ModificadaAlta (7.5)3.0%—Djangoproject DjangoDebian LinuxFedoraproject Fedora3/7/202317/6/2026
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
ModificadaMedia (6.5)8.3%💥 PoCLinux KernelNetapp Active IQ Unified ManagerDebian Linux30/6/202317/6/2026
A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.
ModificadaAlta (7.8)0.67%—Linux KernelCanonical Ubuntu LinuxDebian Linux28/6/202317/6/2026
Una vulnerabilidad de use-after-free en el subsistema de io_uring del kernel de Linux puede ser explotada para lograr la escalada de privilegios locales. Ejecutar una solicitud de io_uring cancelar sondeo con un tiempo de espera vinculado puede provocar una UAF en un hrtimer. Recomendamos actualizar al commit anterior…
ModificadaAlta (7.8)0.49%—Linux KernelDebian Linux28/6/202317/6/2026
Una vulnerabilidad de escritura fuera de los límites de la memoria en el controlador de red ipvlan del kernel de Linux se puede explotar para lograr la escalada de privilegios locales. La escritura fuera de los límites se debe a la falta de inicialización skb-&gt;cb en el controlador de red ipvlan. La vulnerabilidad…
ModificadaAlta (8.8)0.66%—Google ChromeDebian Linux26/6/202317/6/2026
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.2%—Google ChromeDebian Linux26/6/202317/6/2026
Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)56%—Google ChromeDebian Linux26/6/202317/6/2026
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.8)3.9%💥 PoCArtifex GhostscriptDebian LinuxFedoraproject Fedora25/6/202328/8/2026
Artifex Ghostscript a través de 10.01.2 maneja mal la validación de permisos para dispositivos pipe (con el prefijo %pipe% o el prefijo | pipe character).
ModificadaAlta (7.5)2.9%💥 ExploitShibboleth XmltoolingDebian Linux25/6/202317/6/2026
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
ModificadaMedia (4.4)0.26%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+523/6/202317/6/2026
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
ModificadaAlta (7.1)1.4%—Openprinting CupsFedoraproject FedoraDebian LinuxApple Macos22/6/202317/6/2026
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is…
ModificadaAlta (7.5)2.5%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33…
ModificadaAlta (7.5)3.6%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of…
ModificadaAlta (7)0.19%—Linux KernelDebian Linux18/6/202317/6/2026
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.
AnalizadaAlta (7)0.19%—Linux KernelDebian Linux18/6/202326/8/2026
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.
ModificadaAlta (7.8)0.53%💥 PoCLinux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+416/6/202317/6/2026
Se descubrió un problema en fl_set_geneve_opt en net/sched/cls_flower.c en el kernel de Linux antes de 6.3.7. Permite una escritura fuera de los límites en el código flower classifier a través de paquetes TCA_FLOWER_KEY_ENC_OPTS_GENEVE. Esto puede resultar en denegación de servicio o escalada de privilegios.
AnalizadaAlta (7.1)0.48%—Linux KernelDebian Linux16/6/20231/9/2026
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.
ModificadaAlta (7.5)2.0%—Apache Traffic ServerDebian LinuxFedoraproject Fedora14/6/202317/6/2026
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through…