Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2861▲ 225 respecto a la semana anterior
Críticas / altas1331▼ 100 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

8562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.7%—PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxDebian Linux11/8/202330/9/2026
EN EL SCRIPT DE EXTENSIÓN, se encontró una vulnerabilidad de inyección SQL en PostgreSQL si usa @extowner@, @extschema@ o @extschema:...@ dentro de una construcción de cotización (cotización en dólares, '' o ""). Si un administrador ha instalado archivos de una extensión vulnerable, de confianza y no empaquetada, un…
ModificadaMedia (6.5)3.0%—Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+53011/8/202317/6/2026
La exposición de información a través del estado microarquitectónico tras la ejecución transitoria en determinadas unidades de ejecución vectorial de algunos procesadores Intel(R) puede permitir a un usuario autenticado la divulgación potencial de información a través del acceso local.
ModificadaMedia (6.7)0.65%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+49/8/202317/6/2026
Se ha encontrado un fallo en el controlador exFAT del núcleo de Linux. La vulnerabilidad se encuentra en la implementación de la función de reconstrucción de nombres de archivo, que se encarga de leer entradas de nombres de archivo de un índice de directorio y fusionar partes de nombres de archivo pertenecientes a un…
ModificadaMedia (5.5)0.27%—Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux7/8/202317/6/2026
Se ha encontrado un fallo en la funcionalidad TUN/TAP del kernel de Linux. Este problema podría permitir a un usuario local eludir los filtros de red y obtener acceso no autorizado a algunos recursos. Los parches originales que solucionan CVE-2023-1076 son incorrectos o incompletos. El problema es que los siguientes…
ModificadaAlta (7.8)0.56%💥 PoCLinux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+47/8/202317/6/2026
Se encontró una falla de use-after-free en la funcionalidad Netfilter del kernel de Linux al agregar una regla con NFTA_RULE_CHAIN_ID. Esta falla permite a un usuario local bloquear o escalar sus privilegios en el sistema.
ModificadaAlta (7.8)0.19%—Fabasoft CloudFabasoft Cloud Enterprise ClientFabasoft Folio / Egov-suite3/8/202317/6/2026
Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.
ModificadaMedia (5.5)0.23%—Linux KernelRedhat Enterprise LinuxFedoraproject Fedora3/8/202317/6/2026
A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition.
ModificadaMedia (5.5)0.25%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+23/8/202317/6/2026
A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition.
ModificadaMedia (5.5)0.43%—Artifex GhostscriptRedhat Enterprise LinuxFedoraproject FedoraDebian Linux1/8/202323/6/2026
Se ha encontrado un fallo de desbordamiento de búfer en base/gdevdevn.c:1973 en devn_pcx_write_rle() en ghostscript. Este problema puede permitir a un atacante local provocar una denegación de servicio mediante la salida de un archivo PDF manipulado para un dispositivo DEVN con gs.
ModificadaAlta (7.8)0.92%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s+431/7/202317/6/2026
Se encontró una falla de use-after-free en el netfilter del kernel de Linux en la forma en que un usuario activa la función nft_pipapo_remove con el elemento, sin un NFT_SET_EXT_KEY_END. Este problema podría permitir que un usuario local bloquee el sistema o potencialmente aumente sus privilegios en el sistema.
ModificadaMedia (6.5)0.82%—IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway31/7/202317/6/2026
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.
ModificadaMedia (5.4)0.35%—IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway31/7/202317/6/2026
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaAlta (7.1)0.59%—Github Enterprise Server27/7/202317/6/2026
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff within the GitHub pull request UI. To do so, an attacker would need write access to the repository. This vulnerability affected GitHub Enterprise Server versions 3.7.0 and…
ModificadaMedia (4.4)0.25%—Redhat Enterprise LinuxFedoraproject FedoraLinux KernelDebian Linux25/7/202317/6/2026
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to…
ModificadaMedia (4.4)0.45%—Redhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFVFedoraproject Fedora+225/7/202317/6/2026
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.
ModificadaAlta (7.8)0.34%—Linux KernelRedhat Enterprise Linux24/7/202317/6/2026
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
ModificadaMedia (5.3)0.76%—Redhat LibvirtRedhat Enterprise Linux24/7/202317/6/2026
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.
ModificadaAlta (7.8)0.76%💥 PoCLinux KernelRedhat Enterprise Linux24/7/202321/7/2026
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in…
ModificadaAlta (7.1)0.42%—Linux KernelRedhat Enterprise LinuxCanonical Ubuntu Linux24/7/202317/6/2026
A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.
ModificadaMedia (6.5)0.32%—QemuRedhat Enterprise Linux24/7/202317/6/2026
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
ModificadaAlta (7.5)1.4%—KeylimeRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+524/7/202317/6/2026
Se encontró una falla en Keylime. Debido a su naturaleza de bloqueo, el registrador de Keylime está sujeto a una denegación de servicio remota contra sus conexiones SSL. Esta falla permite a un atacante agotar todas las conexiones disponibles.
ModificadaMedia (6.7)0.46%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV24/7/202317/6/2026
Se encontró una vulnerabilidad de double free en el manejo de objetos vmw_buffer_object en el controlador vmwgfx en el kernel de Linux. Este problema se produce debido a la falta de validación de la existencia de un objeto antes de realizar más operaciones libres en el objeto, lo que puede permitir a un usuario…
ModificadaMedia (5.3)0.34%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV24/7/202317/6/2026
Se encontró una vulnerabilidad de condición de ejecución en el controlador vmwgfx del kernel de Linux. El fallo existe en el manejo de objetos GEM. El problema se debe a un bloqueo inadecuado al realizar operaciones en un objeto. Este fallo permite que un usuario local privilegiado revele información en el contexto…
ModificadaCrítica (9.8)0.45%—GSS Vitals Enterprise Social Platform21/7/202317/6/2026
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
ModificadaMedia (5.9)0.44%—SambaRedhat StorageRedhat Enterprise LinuxFedoraproject Fedora20/7/202317/6/2026
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a…