Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
8474 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 0.35% | — | Linux KernelRedhat Enterprise Linux | 18/5/2023 | 17/6/2026 | The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device. | |
| Modificada | Crítica (9.8) | 0.97% | — | Clusterlabs PCSRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUS | 17/5/2023 | 17/6/2026 | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was… | |
| Modificada | Alta (7.5) | 1.6% | — | LibreswanRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+1 | 17/5/2023 | 17/6/2026 | A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder… | |
| Modificada | Media (5.5) | 0.43% | — | LibtiffFedoraproject FedoraRedhat Enterprise Linux | 17/5/2023 | 17/6/2026 | A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service. | |
| Modificada | Alta (7.8) | 0.46% | — | GNU EmacsRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+1 | 17/5/2023 | 17/6/2026 | A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat… | |
| Modificada | Alta (8.8) | 0.93% | — | Webkitgtk Webkit2gtk3Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+1 | 17/5/2023 | 17/6/2026 | A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205… | |
| Modificada | Media (4.3) | 0.58% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data… | |
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Media (5.5) | 0.25% | — | Redhat LibvirtFedoraproject FedoraRedhat Enterprise Linux | 15/5/2023 | 17/6/2026 | A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup. | |
| Analizada | Media (6.5) | 1.3% | — | LibrawFedoraproject FedoraRedhat Enterprise Linux | 15/5/2023 | 17/6/2026 | A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash. | |
| Modificada | Alta (8.1) | 1.5% | — | Loadbalancer Enterprise VA MAX | 12/5/2023 | 17/6/2026 | The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and write access to sensitive files. | |
| Modificada | Alta (8.8) | 3.3% | — | Loadbalancer Enterprise VA MAX | 12/5/2023 | 17/6/2026 | Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code. | |
| Modificada | Media (6.5) | 0.88% | — | QTRedhat Enterprise Linux | 10/5/2023 | 17/6/2026 | In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled. | |
| Modificada | Alta (7.5) | 6.1% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 9/5/2023 | 17/6/2026 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the… | |
| Analizada | Alta (7.2) | 85% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 1.8% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20h2+10 | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 67% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability |