Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

8562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.3%—SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+120/7/202317/6/2026
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part…
ModificadaMedia (5.3)61%—SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux20/7/202317/6/2026
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of…
ModificadaAlta (7.5)62%—SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux20/7/202317/6/2026
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing…
ModificadaMedia (5.9)1.7%—SambaRedhat Enterprise LinuxFedoraproject FedoraDebian Linux20/7/202317/6/2026
An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length.…
ModificadaMedia (6.5)0.45%—Microfocus Cobol ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Test Server+120/7/202317/6/2026
A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this…
ModificadaMedia (6.1)0.37%—Oracle JD Edwards Enterpriseone Tools18/7/202317/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.…
ModificadaMedia (5.4)0.38%—Oracle JD Edwards Enterpriseone Orchestrator18/7/202317/6/2026
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.7.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards…
ModificadaAlta (7.5)77%💥 ExploitOracle Peoplesoft Enterprise18/7/202317/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful…
ModificadaAlta (8.4)0.21%—Oracle Peoplesoft Enterprise Peopletools18/7/202317/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to…
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (6.5)1.2%—LibtiffDebian LinuxRedhat Enterprise Linux12/7/202317/6/2026
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
ModificadaAlta (7.5)1.6%—QemuRedhat Openstack PlatformRedhat Enterprise LinuxFedoraproject Fedora11/7/202317/6/2026
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the…
ModificadaAlta (7.8)1.3%💥 PoCLinux KernelFedoraproject FedoraRedhat Enterprise Linux11/7/202317/6/2026
A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root…
ModificadaMedia (5.3)0.57%—Tang Project TangFedoraproject FedoraRedhat Enterprise Linux11/7/202317/6/2026
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
ModificadaAlta (7.8)0.39%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
ModificadaAlta (7.8)0.27%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
ModificadaMedia (5.5)0.28%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
ModificadaMedia (5.5)0.21%—Sound Exchange Project Sound ExchangeFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
ModificadaMedia (5.5)65%—LibreofficeFedoraproject FedoraRedhat Enterprise Linux10/7/202317/6/2026
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
ModificadaAlta (8.8)0.94%—Trellix Enterprise Security Manager3/7/202317/6/2026
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain…
ModificadaAlta (7.8)0.47%—Trellix Enterprise Security Manager3/7/202317/6/2026
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands.
ModificadaMedia (5.7)0.55%💥 PoCLinux KernelRedhat Enterprise LinuxFedoraproject Fedora30/6/202317/6/2026
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.
ModificadaAlta (7.5)1.7%—X.org Libx11Redhat Enterprise Linux28/6/202317/6/2026
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called…
ModificadaMedia (4.4)0.26%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+523/6/202317/6/2026
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.