Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2834▲ 81 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

10.010 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.9%💥 ExploitShibboleth XmltoolingDebian Linux25/6/202317/6/2026
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
ModificadaMedia (4.4)0.26%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+523/6/202317/6/2026
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
ModificadaAlta (7.1)1.4%—Openprinting CupsFedoraproject FedoraDebian LinuxApple Macos22/6/202317/6/2026
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is…
ModificadaAlta (7.5)2.5%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33…
ModificadaAlta (7.5)3.6%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+521/6/202317/6/2026
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of…
ModificadaAlta (7)0.19%—Linux KernelDebian Linux18/6/202317/6/2026
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.
AnalizadaAlta (7)0.19%—Linux KernelDebian Linux18/6/202326/8/2026
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.
ModificadaAlta (7.8)0.53%💥 PoCLinux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+416/6/202317/6/2026
Se descubrió un problema en fl_set_geneve_opt en net/sched/cls_flower.c en el kernel de Linux antes de 6.3.7. Permite una escritura fuera de los límites en el código flower classifier a través de paquetes TCA_FLOWER_KEY_ENC_OPTS_GENEVE. Esto puede resultar en denegación de servicio o escalada de privilegios.
AnalizadaAlta (7.1)0.48%—Linux KernelDebian Linux16/6/20231/9/2026
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.
ModificadaAlta (7.5)2.0%—Apache Traffic ServerDebian LinuxFedoraproject Fedora14/6/202317/6/2026
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through…
ModificadaAlta (7.5)1.5%—Apache Traffic ServerDebian Linux14/6/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.
ModificadaAlta (8.8)13%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.94%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)14%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.94%—Google ChromeDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
AnalizadaBaja (3.9)14%⚠ Explotación activaVmware ToolsDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada.
ModificadaAlta (7.1)0.44%—Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux9/6/202317/6/2026
A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.
ModificadaMedia (6.5)1.4%—Freedesktop DbusFedoraproject FedoraDebian Linux8/6/202317/6/2026
D-Bus en versiones anteriores a v1.15.6 a veces permite a usuarios sin privilegios bloquear el "dbus-daemon". Si un usuario privilegiado con control sobre "dbus-daemon" está usando la interfaz "org.freedesktop.DBus.Monitoring" para monitorizar el tráfico del bus de mensajes, entonces un usuario sin privilegios con la…
ModificadaMedia (6.5)2.3%—WiresharkDebian Linux7/6/202317/6/2026
Debido a un fallo en la validación de la longitud proporcionada por un atacante de paquetes IEEE-C37.118, Wireshark v4.0.5 y anteriores, por defecto, es susceptible a un desbordamiento de búfer de la pila, y posiblemente la ejecución de código en el contexto del proceso que ejecuta Wireshark.
ModificadaMedia (6.5)2.3%—WiresharkDebian Linux7/6/202317/6/2026
Debido a un fallo en la validación de la longitud proporcionada por un atacante de paquetes manipulados RTPS, Wireshark v4.0.5 y anteriores, por defecto, es susceptible a un desbordamiento de búfer de pila y posiblemente la ejecución de código en el contexto del proceso que ejecuta Wireshark.
ModificadaAlta (7.8)0.58%💥 PoCLibcap Project LibcapRedhat Enterprise LinuxFedoraproject FedoraDebian Linux6/6/202317/6/2026
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
ModificadaBaja (3.3)0.35%—Libcap Project LibcapRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora6/6/202317/6/2026
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
ModificadaMedia (6.5)1.1%—Yajl Project YajlFedoraproject FedoraDebian Linux6/6/202317/6/2026
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
ModificadaAlta (7.8)0.44%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+35/6/202317/6/2026
A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
AnalizadaAlta (8.8)38%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject FedoraDebian LinuxCouchbase Server5/6/20238/10/2026
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)