Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
3731 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.40% | — | Gnome LibsoupRedhat Enterprise Linux | 23/4/2026 | 17/6/2026 | A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP… | |
| Modificada | Alta (8.8) | 0.77% | — | Redhat InstructlabRedhat Enterprise Linux AI | 22/4/2026 | 15/7/2026 | A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ilab train/download/generate` with a specially crafted malicious model from the… | |
| Analizada | Alta (7.1) | 0.22% | — | Redhat InstructlabRedhat Enterprise Linux AI | 22/4/2026 | 17/6/2026 | A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data… | |
| Modificada | Alta (7.8) | 0.20% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the… | |
| Modificada | Media (5) | 0.14% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming… | |
| Analizada | Media (5.5) | 0.15% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The… | |
| Analizada | Media (5.5) | 0.15% | — | GNU NanoRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Alta (7.8) | 0.22% | — | Ocaml OpamDebian LinuxRedhat Enterprise Linux | 16/4/2026 | 15/7/2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. | |
| Analizada | Media (5.5) | 0.33% | — | GimpRedhat Enterprise Linux | 15/4/2026 | 17/6/2026 | A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potentially impacting the… | |
| Analizada | Media (5.5) | 0.26% | — | GimpRedhat Enterprise Linux | 15/4/2026 | 17/6/2026 | A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PVR image files are… | |
| Analizada | Alta (7.1) | 0.22% | — | GimpRedhat Enterprise Linux | 15/4/2026 | 17/6/2026 | A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files. | |
| Analizada | Media (5.5) | 0.22% | — | GimpRedhat Enterprise Linux | 15/4/2026 | 17/6/2026 | A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array. | |
| Analizada | Alta (7.8) | 0.40% | — | GimpRedhat Enterprise Linux | 15/4/2026 | 17/6/2026 | A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data. Successful… | |
| Analizada | Media (5.5) | 0.15% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 15/4/2026 | 1/9/2026 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read… | |
| Modificada | Alta (7.8) | 0.30% | — | GimpRedhat Enterprise Linux | 15/4/2026 | 30/9/2026 | A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution. | |
| Analizada | Alta (7.5) | 6.6% | ⚠ Explotación activa💥 Exploit | Apache TomcatRedhat Jboss WEB ServerRedhat Enterprise LinuxRedhat Enterprise Linux ELS+3 | 9/4/2026 | 21/9/2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. | |
| Modificada | Alta (7) | 0.14% | — | Libcap Project LibcapRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/4/2026 | 2/10/2026 | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be… | |
| Modificada | Media (5.5) | 0.17% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/4/2026 | 1/9/2026 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate… | |
| Modificada | Media (5.5) | 0.40% | — | GNU TARRedhat Hardened ImagesRedhat Enterprise Linux | 6/4/2026 | 22/9/2026 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without… | |
| Analizada | Alta (7.1) | 0.16% | — | Xiph TheoraRedhat Enterprise Linux | 6/4/2026 | 17/6/2026 | A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header… | |
| Analizada | Media (5.5) | 0.11% | — | Redhat Hardened ImagesSequoia-pgp Rpm-sequoiaRedhat Enterprise Linux | 3/4/2026 | 24/7/2026 | A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of… | |
| Modificada | Alta (7.5) | 1.3% | — | CorosyncRedhat OpenshiftRedhat Enterprise Linux | 1/4/2026 | 21/8/2026 | A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects… | |
| Modificada | Alta (8.2) | 1.1% | — | CorosyncRedhat OpenshiftRedhat Enterprise Linux | 1/4/2026 | 21/8/2026 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and… | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | Gnome Gdk-pixbufRedhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server TUS | 31/3/2026 | 15/7/2026 | A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail… |