Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

10.010 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)2.6%—Ruby-lang URIDebian LinuxFedoraproject Fedora31/3/202317/6/2026
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
ModificadaMedia (5.5)1.2%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+730/3/202317/6/2026
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the…
ModificadaMedia (5.9)1.6%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+630/3/202317/6/2026
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI…
ModificadaMedia (5.9)1.6%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+630/3/202317/6/2026
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as…
ModificadaCrítica (9.8)4.4%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of…
ModificadaCrítica (9.8)2.8%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which…
ModificadaCrítica (9.8)3.8%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper validation of user-supplied data, which…
ModificadaCrítica (9.8)4.4%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper validation of the length of user-supplied data…
ModificadaCrítica (9.8)8.6%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble…
ModificadaCrítica (9.8)4.4%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data…
ModificadaAlta (7)0.28%—Linux KernelDebian LinuxNetapp A700s FirmwareNetapp 8300 Firmware+827/3/202317/6/2026
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing…
ModificadaAlta (7.1)17%—Redhat Enterprise LinuxLinux KernelNetapp H500s FirmwareNetapp H700s Firmware+527/3/202317/9/2026
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
ModificadaAlta (7.1)0.70%—DinoFedoraproject FedoraDebian Linux24/3/202317/6/2026
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
AnalizadaAlta (7.8)7.9%⚠ Explotación activa💥 ExploitDebian LinuxNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+422/3/202317/6/2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on…
ModificadaMedia (6.5)0.27%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would…
ModificadaAlta (8.6)1.2%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would…
ModificadaAlta (7.8)0.27%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data…
ModificadaAlta (7)0.27%—Linux KernelNetapp H300sNetapp H410cNetapp H410s+316/3/202317/6/2026
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
ModificadaAlta (7.5)1.8%—RackDebian Linux10/3/202317/6/2026
A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
AnalizadaAlta (7.5)2.1%—Apache Http ServerDebian LinuxUnbit Uwsgi7/3/202317/6/2026
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
ModificadaMedia (6)0.25%—QemuDebian Linux6/3/202317/6/2026
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
ModificadaAlta (7.1)0.65%—WiresharkDebian Linux6/3/202317/6/2026
El fallo del disector ISO 15765 e ISO 10681 en Wireshark 4.0.0 a 4.0.3 y 3.6.0 a 3.6.11 permite la denegación de servicio mediante la inyección de paquetes o un archivo de captura manipulado.
AnalizadaMedia (6.6)0.45%—Debian LinuxFedoraproject FedoraNeovimVIM4/3/202318/9/2026
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
ModificadaAlta (7)0.45%—Linuxfoundation RuncRedhat Openshift Container PlatformRedhat Enterprise LinuxDebian Linux3/3/202317/6/2026
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921…
AnalizadaAlta (7.8)1.1%—Debian LinuxSystemd Project Systemd3/3/202317/6/2026
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a…