Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 79 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

10.167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.28%—Linux KernelDebian LinuxNetapp A700s FirmwareNetapp 8300 Firmware+827/3/202317/6/2026
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing…
ModificadaAlta (7.1)17%—Redhat Enterprise LinuxLinux KernelNetapp H500s FirmwareNetapp H700s Firmware+527/3/202317/9/2026
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
ModificadaAlta (7.1)0.70%—DinoFedoraproject FedoraDebian Linux24/3/202317/6/2026
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
AnalizadaAlta (7.8)7.9%⚠ Explotación activa💥 ExploitDebian LinuxNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+422/3/202317/6/2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on…
ModificadaMedia (6.5)0.27%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would…
ModificadaAlta (8.6)1.2%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would…
ModificadaAlta (7.8)0.27%—XENDebian LinuxFedoraproject Fedora21/3/202317/6/2026
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data…
ModificadaAlta (7)0.27%—Linux KernelNetapp H300sNetapp H410cNetapp H410s+316/3/202317/6/2026
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
ModificadaAlta (7.5)1.8%—RackDebian Linux10/3/202317/6/2026
A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
AnalizadaAlta (7.5)2.1%—Apache Http ServerDebian LinuxUnbit Uwsgi7/3/202317/6/2026
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
ModificadaMedia (6)0.25%—QemuDebian Linux6/3/202317/6/2026
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
ModificadaAlta (7.1)0.65%—WiresharkDebian Linux6/3/202317/6/2026
El fallo del disector ISO 15765 e ISO 10681 en Wireshark 4.0.0 a 4.0.3 y 3.6.0 a 3.6.11 permite la denegación de servicio mediante la inyección de paquetes o un archivo de captura manipulado.
ModificadaAlta (7.8)0.44%—Debian Debmany5/3/202317/6/2026
debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)
AnalizadaMedia (6.6)0.45%—Debian LinuxFedoraproject FedoraNeovimVIM4/3/202318/9/2026
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
ModificadaAlta (7)0.45%—Linuxfoundation RuncRedhat Openshift Container PlatformRedhat Enterprise LinuxDebian Linux3/3/202317/6/2026
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921…
AnalizadaAlta (7.8)1.1%—Debian LinuxSystemd Project Systemd3/3/202317/6/2026
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a…
ModificadaAlta (7.8)0.33%—Struktur Libde265Debian Linux1/3/202317/6/2026
Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (6.5)0.77%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaCrítica (9.8)100%💥 ExploitSpipDebian Linux28/2/202317/6/2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.