Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
–

10.010 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.7)0.72%—Linux KernelDebian Linux26/4/202317/6/2026
A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading past version 6.1.8 or commit…
ModificadaAlta (7.5)2.4%💥 PoCLinux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+425/4/202317/6/2026
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the…
ModificadaMedia (4.4)0.22%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+425/4/20238/10/2026
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
ModificadaAlta (7.8)0.29%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+424/4/202317/6/2026
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
ModificadaMedia (6.5)1.0%—Xmlsoft Libxml2Debian Linux24/4/202317/6/2026
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of…
ModificadaMedia (6.5)0.94%—Xmlsoft Libxml2Debian Linux24/4/202317/6/2026
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
ModificadaMedia (5.5)0.41%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware24/4/202317/6/2026
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem)…
ModificadaMedia (5.6)1.4%💥 ExploitLinux KernelDebian Linux21/4/202317/6/2026
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel still left the victim process exposed to attacks in some cases…
ModificadaAlta (8.8)1.1%—Google ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
AnalizadaCrítica (9.6)5.7%⚠ Explotación activaGoogle ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.5)1.0%—Google ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.1%—Google ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.1%—Google ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.5)0.98%—Sqlparse Project SqlparseDebian Linux18/4/202317/6/2026
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been…
ModificadaMedia (6.5)1.3%—RedisDebian LinuxFedoraproject Fedora18/4/202317/6/2026
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There…
ModificadaMedia (5.3)1.3%💥 PoCEclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+218/4/202317/6/2026
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will…
ModificadaBaja (3.7)1.0%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability…
ModificadaMedia (5.9)1.5%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows…
ModificadaMedia (5.9)1.4%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows…
ModificadaMedia (5.3)2.5%💥 PoCOracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows…
ModificadaBaja (3.7)1.2%—Oracle GraalvmOracle JDKOracle JREDebian Linux+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Difficult to exploit vulnerability…
ModificadaBaja (3.7)1.2%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability…
ModificadaAlta (7.4)1.3%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows…
AnalizadaAlta (8.8)41%⚠ Explotación activa💥 PoCGoogle ChromeDebian LinuxFedoraproject FedoraCouchbase Server14/4/202317/6/2026
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaMedia (6.5)1.0%—WiresharkDebian LinuxFedoraproject Fedora12/4/202317/6/2026
El fallo del disector GQUIC en Wireshark 4.0.0 a 4.0.4 y 3.6.0 a 3.6.12 permite la denegación de servicio mediante la inyección de paquetes o un archivo de captura manipulado.