Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

10.167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.8%—WiresharkDebian Linux26/5/202317/6/2026
El fallo del analizador de archivos BLF en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado.
ModificadaMedia (6.5)0.88%—WiresharkDebian Linux26/5/202317/6/2026
El fallo del analizador de archivos BLF en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado.
ModificadaMedia (6.5)1.8%—WiresharkDebian Linux26/5/202317/6/2026
El fallo del analizador de archivos VMS TCPIPtrace en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado.
ModificadaMedia (6.5)1.6%—WiresharkDebian Linux26/5/202317/6/2026
La falla del analizador de registros de Candump en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado
ModificadaMedia (6.5)0.88%—WiresharkDebian Linux26/5/202317/6/2026
El fallo del analizador de archivos BLF en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado.
ModificadaMedia (5.9)1.8%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+626/5/202317/6/2026
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private…
ModificadaMedia (6.5)1.3%—LibsshFedoraproject FedoraDebian LinuxRedhat Enterprise Linux26/5/202317/6/2026
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
ModificadaMedia (6.8)1.5%💥 PoCLinux KernelDebian Linux26/5/202317/6/2026
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.
ModificadaAlta (7.5)1.6%—C-ares Project C-aresFedoraproject FedoraDebian Linux25/5/202317/6/2026
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the…
ModificadaMedia (6.4)0.38%—C-ares Project C-aresFedoraproject FedoraDebian Linux25/5/202317/6/2026
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an…
ModificadaMedia (5.3)2.2%💥 PoCLibreofficeDebian Linux25/5/202317/6/2026
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of…
ModificadaAlta (7.8)0.30%—LibreofficeDebian Linux25/5/202317/6/2026
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as…
ModificadaAlta (7.5)48%—Apache TomcatDebian LinuxNetapp 7-mode Transition Tool22/5/202317/6/2026
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly…
ModificadaAlta (7.8)0.33%—Sysstat Project SysstatFedoraproject FedoraDebian Linux18/5/202317/6/2026
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
ModificadaAlta (8.8)3.7%—Linuxfoundation Cups-filtersFedoraproject FedoraDebian Linux17/5/202317/6/2026
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line…
ModificadaAlta (8.8)0.68%—Google ChromeDebian LinuxFedoraproject Fedora16/5/202317/6/2026
Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)25%—Google ChromeDebian LinuxFedoraproject Fedora16/5/202317/6/2026
Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)29%—Google ChromeDebian LinuxFedoraproject Fedora16/5/202317/6/2026
Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)15%—Google ChromeDebian LinuxFedoraproject Fedora16/5/202317/6/2026
Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.85%—Google ChromeDebian LinuxFedoraproject Fedora16/5/202317/6/2026
Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)0.87%—Google ChromeDebian LinuxFedoraproject Fedora16/5/202317/6/2026
Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
ModificadaAlta (7.8)0.49%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+315/5/202317/6/2026
An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.
ModificadaAlta (7.5)6.1%—Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux9/5/202317/6/2026
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the…
ModificadaAlta (7.5)2.2%—FrroutingDebian LinuxFedoraproject Fedora9/5/202317/6/2026
Un problema encontrado en Frrouting bgpd v.8.4.2 permite a un atacante remoto causar una denegación de servicio a través de la función bgp_attr_psid_sub().
ModificadaAlta (7.5)1.1%—MaradnsFedoraproject FedoraDebian Linux9/5/202317/6/2026
MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination. The vulnerability…