Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

4007 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.4)0.21%—Opensuse Factory14/1/202217/6/2026
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.
ModificadaMedia (5.5)1.1%—Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+36/1/202217/6/2026
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
ModificadaMedia (5.5)1.1%—Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+36/1/202217/6/2026
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
ModificadaAlta (7.5)2.9%—Ruby-lang CGIRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
ModificadaAlta (7.5)3.2%—Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+51/1/202217/6/2026
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
ModificadaAlta (7.1)1.6%—VIMRedhat Enterprise LinuxOpensuse FactorySuse Linux Enterprise+425/12/202117/6/2026
vim is vulnerable to Out-of-bounds Read
AnalizadaAlta (7.5)25%💥 PoCBalasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaAlta (7.5)1.4%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaAlta (7.5)1.5%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaAlta (7.5)1.4%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaAlta (7.5)1.5%—Opensuse Libsolv2/9/202117/6/2026
Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
ModificadaCrítica (9.8)2.7%—Artixlinux Opensysusers25/8/202117/6/2026
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.
ModificadaMedia (6.5)0.30%—Suse Rancher K3SSuse Rancher Rke228/7/202117/6/2026
K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This…
ModificadaAlta (7.1)0.30%—Suse Linux Enterprise ServerOpensuse Factory28/7/202117/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3…
ModificadaAlta (7.8)0.44%—Suse Arpwatch30/6/202117/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of…
ModificadaCrítica (9.8)1.1%—Opensuse Cryptctl30/6/202117/6/2026
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE…
ModificadaAlta (7.8)0.32%—Opensuse INN10/6/202117/6/2026
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version…
ModificadaAlta (7.8)0.34%—Opensuse Python-postorius10/6/202117/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory…
ModificadaAlta (7.1)0.39%—Lrzsz Project LrzszSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Server+12/6/202117/6/2026
lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
ModificadaBaja (3.3)1.3%—Opensuse LibsolvOracle Communications Cloud Native Core Policy18/5/202117/6/2026
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
ModificadaBaja (3.3)0.27%—Suse CupsFedoraproject Fedora5/5/202117/6/2026
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability…
ModificadaAlta (7.8)0.26%—Opensuse Factory5/5/202117/6/2026
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
ModificadaAlta (7.8)0.38%—Suse Hawk214/4/202117/6/2026
A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue affects: SUSE Linux Enterprise High…
ModificadaBaja (3.3)0.32%—Suse S390-tools14/4/202117/6/2026
A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-SP2 allows local attackers to prevent VM live migrations This issue affects: SUSE Linux Enterprise Server 12-SP5 s390-tools versions prior to 2.1.0-18.29.1. SUSE Linux Enterprise Server 15-SP2…
ModificadaMedia (6.1)1.5%—Suse Rancher5/3/202117/6/2026
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.