Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
4241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 2.3% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+2 | 21/10/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.1) | 2.3% | — | Linuxfoundation ContainerdCanonical Ubuntu LinuxDebian Linux | 16/10/2020 | 17/6/2026 | In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the… | |
| Modificada | Alta (7.5) | 2.4% | — | Linux KernelDebian LinuxNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+3 | 13/10/2020 | 17/6/2026 | A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this… | |
| Modificada | Media (6.6) | 2.7% | — | Spice Project SpiceRedhat OpenstackCanonical Ubuntu LinuxDebian Linux+6 | 7/10/2020 | 17/6/2026 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when… | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+1 | 6/10/2020 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block… | |
| Modificada | Media (5.3) | 5.0% | — | PHPFedoraproject FedoraDebian LinuxOpensuse Leap+3 | 2/10/2020 | 17/6/2026 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge… | |
| Modificada | Media (6.5) | 2.1% | — | PHPFedoraproject FedoraDebian LinuxOpensuse Leap+4 | 2/10/2020 | 17/6/2026 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data. | |
| Modificada | Alta (8.8) | 0.43% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to any address in the vhost_crypto application. The highest threat from this vulnerability is to data… | |
| Modificada | Baja (3.3) | 0.40% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used… | |
| Modificada | Alta (7.1) | 0.41% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual… | |
| Modificada | Alta (7.8) | 0.40% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Alta (7.8) | 0.25% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest… | |
| Modificada | Media (6.5) | 2.3% | — | Python Urllib3Canonical Ubuntu LinuxDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+1 | 30/9/2020 | 17/6/2026 | urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116. | |
| Modificada | Alta (7.2) | 6.4% | — | PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+4 | 27/9/2020 | 17/6/2026 | http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | |
| Modificada | Media (5.5) | 0.40% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 24/9/2020 | 17/6/2026 | A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a. | |
| Modificada | Media (6.1) | 1.4% | — | GON Project GONCanonical Ubuntu LinuxDebian Linux | 23/9/2020 | 17/6/2026 | An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. | |
| Modificada | Media (4.7) | 0.49% | — | Perl DBIFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+1 | 17/9/2020 | 17/6/2026 | An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference. | |
| Modificada | Alta (7.8) | 1.2% | — | Cryptsetup Project CryptsetupRedhat Enterprise LinuxCanonical Ubuntu LinuxFedoraproject Fedora | 16/9/2020 | 17/6/2026 | A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function… | |
| Modificada | Media (5.5) | 0.55% | — | Perl Database InterfaceCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+1 | 16/9/2020 | 17/6/2026 | An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. | |
| Modificada | Media (5.5) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxDebian Linux | 15/9/2020 | 17/6/2026 | A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a… | |
| Modificada | Media (5.5) | 0.37% | — | Linux KernelDebian LinuxCanonical Ubuntu LinuxStarwindsoftware Starwind Virtual SAN | 15/9/2020 | 17/6/2026 | A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (7.8) | 0.59% | — | X.org X ServerCanonical Ubuntu LinuxRedhat Enterprise Linux | 15/9/2020 | 17/6/2026 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Alta (7.8) | 0.61% | — | X.org X ServerCanonical Ubuntu LinuxRedhat Enterprise Linux | 15/9/2020 | 17/6/2026 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Alta (7.8) | 0.63% | — | X.org X ServerCanonical Ubuntu LinuxRedhat Enterprise Linux | 15/9/2020 | 17/6/2026 | A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Alta (7.8) | 0.59% | — | X.org X ServerCanonical Ubuntu Linux | 15/9/2020 | 17/6/2026 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |