Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2834▲ 197 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

10.010 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)4.1%—WiresharkDebian LinuxFedoraproject Fedora12/4/202317/6/2026
El bucle grande del disector LISP en Wireshark 4.0.0 a 4.0.4 y 3.6.0 a 3.6.12 permite la denegación de servicio mediante inyección de paquetes o archivo de captura manipulado
ModificadaAlta (7.5)4.6%—WiresharkDebian LinuxFedoraproject Fedora12/4/202317/6/2026
El fallo del disector RPCoRDMA en Wireshark 4.0.0 a 4.0.4 y 3.6.0 a 3.6.12 permite la denegación de servicio mediante la inyección de paquetes o un archivo de captura manipulado.
ModificadaAlta (7)0.29%—Linux KernelDebian Linux12/4/202317/6/2026
A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation. The io_file_get_fixed function lacks the presence of ctx->uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered. We recommend…
ModificadaAlta (7)0.44%—Linux KernelNetapp H300sNetapp H410cNetapp H410s+311/4/20231/10/2026
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices.
ModificadaAlta (8.2)1.2%—Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+210/4/202317/6/2026
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,…
ModificadaMedia (5.5)0.20%—Canonical Ubuntu LinuxDebian Linux7/4/202317/6/2026
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.
ModificadaMedia (6.5)0.89%—Bzip3 Project Bzip3Debian Linux6/4/202317/6/2026
An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais.
ModificadaMedia (6.3)0.23%—Linux KernelDebian Linux5/4/202317/6/2026
A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem.
ModificadaMedia (6.5)0.95%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (6.5)0.98%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (6.5)0.91%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
ModificadaAlta (8.8)0.97%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.88%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.88%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.97%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.91%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.91%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.95%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.76%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.94%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.97%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (8.8)1.1%—Google ChromeFedoraproject FedoraDebian Linux4/4/202317/6/2026
Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaAlta (7.5)1.6%—FrroutingFedoraproject FedoraDebian Linux3/4/202317/6/2026
Se encontró una afirmación accesible en Frrouting frr-bgpd 8.3.0 en la función peek_for_as4_capability. Los atacantes pueden construir maliciosamente paquetes abiertos BGP y enviarlos a pares BGP que ejecutan frr-bgpd, lo que resulta en DoS.
ModificadaCrítica (9.8)6.3%—Artifex GhostscriptDebian Linux31/3/202317/6/2026
En Artifex Ghostscript hasta la versión 10.01.0, hay un desbordamiento de búfer que puede corromper los datos internos del intérprete PostScript, en base/sbcp.c. Esto afecta a BCPEncode, BCPDecode, TBCPEncode y TBCPDecode. Si el búfer de escritura se llena hasta un byte menos de su capacidad, y se intenta escribir un…
ModificadaMedia (5.3)2.5%—Ruby-lang RubyRuby-lang TimeDebian LinuxFedoraproject Fedora31/3/202317/6/2026
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.