Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

8474 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—X.org Libx11Redhat Enterprise Linux28/6/202317/6/2026
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called…
ModificadaMedia (4.4)0.26%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+523/6/202317/6/2026
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
AnalizadaAlta (8.8)12%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+423/6/202317/6/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that…
ModificadaAlta (7.7)0.42%—Hashicorp Terraform Enterprise22/6/202317/6/2026
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged workspace in the same organization that…
ModificadaMedia (5.5)0.50%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.35%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (5.5)0.37%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/6/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
ModificadaCrítica (9.8)1.5%—HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+95314/6/202317/6/2026
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.
ModificadaMedia (5.5)0.20%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux12/6/202317/6/2026
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
ModificadaMedia (5.4)0.69%—PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora9/6/202317/6/2026
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or…
ModificadaAlta (7.2)1.2%—PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora9/6/202317/6/2026
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
ModificadaCrítica (9.8)1.1%—Puppet Enterprise7/6/202317/6/2026
Se descubrió una escalada de privilegios que permite la ejecución remota de código en el servicio de orquestación.
ModificadaAlta (7.8)0.58%💥 PoCLibcap Project LibcapRedhat Enterprise LinuxFedoraproject FedoraDebian Linux6/6/202317/6/2026
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
ModificadaBaja (3.3)0.35%—Libcap Project LibcapRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora6/6/202317/6/2026
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
ModificadaAlta (7.1)0.29%—Opensc Project OpenscRedhat Enterprise Linux1/6/202317/6/2026
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly…
ModificadaMedia (5.5)0.25%—Linux KernelSuse Linux EnterpriseDebian Linux31/5/202317/6/2026
Se ha descubierto un problema en el kernel de Linux en las versiones anteriores a 6.3.3. Hay una lectura fuera de límites en crc16 en "lib/crc16.c" cuando se llama dese "fs/ext4/super.c" porque "ext4_group_desc_csum" no comprueba correctamente un desplazamiento.
AnalizadaAlta (7.8)3.1%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
ModificadaCrítica (9.8)8.0%💥 PoCImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux30/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
AnalizadaMedia (5.5)0.95%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+130/5/202317/6/2026
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
ModificadaAlta (7.5)1.9%—OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+730/5/202317/6/2026
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
ModificadaMedia (6.5)1.1%—LibsshFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,`…
ModificadaMedia (5.5)0.39%—AvahiFedoraproject FedoraRedhat Enterprise Linux26/5/202317/6/2026
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
ModificadaMedia (6.5)1.3%—LibsshFedoraproject FedoraDebian LinuxRedhat Enterprise Linux26/5/202317/6/2026
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
ModificadaMedia (6.5)0.52%—Johnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
ModificadaAlta (7.5)1.1%💥 PoCJohnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.