Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

8562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.44%—Puppet EnterprisePuppet Server4/5/202317/6/2026
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.
ModificadaAlta (7.3)1.1%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora2/5/202317/6/2026
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
ModificadaMedia (5.3)6.6%💥 ExploitMoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora2/5/202317/6/2026
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
ModificadaAlta (7.8)0.37%—Lfprojects ApptainerSylabs SingularityRedhat Enterprise Linux25/4/202317/6/2026
Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. That includes Red Hat Enterprise Linux 7, Debian…
AnalizadaAlta (7.5)64%⚠ Explotación activaNetapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+125/4/202317/6/2026
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
ModificadaMedia (4.4)0.34%—Linux KernelRedhat Enterprise Linux24/4/202317/6/2026
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
ModificadaAlta (7.5)0.43%—Enterprisedb Postgres Advanced Server23/4/202317/6/2026
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and…
ModificadaMedia (6.7)0.24%—Linux KernelFedoraproject FedoraRedhat Enterprise Linux20/4/202317/6/2026
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash…
ModificadaMedia (5.5)0.22%—Linux KernelRedhat Enterprise Linux19/4/202317/6/2026
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.
ModificadaMedia (5.5)0.19%—Linux KernelRedhat Enterprise Linux19/4/202317/6/2026
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.
ModificadaMedia (5.4)0.41%—Oracle Peoplesoft Enterprise Human Capital Management Human Resources18/4/202317/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Administer Workforce). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human…
ModificadaMedia (4.9)0.63%—Oracle Peoplesoft Enterprise Peopletools18/4/202317/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
ModificadaMedia (5.4)0.38%—Oracle JD Edwards Enterpriseone Tools18/4/202317/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful…
ModificadaMedia (4.3)0.48%—Oracle JD Edwards Enterpriseone Tools18/4/202317/6/2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.…
ModificadaMedia (5.3)0.51%—Oracle Peoplesoft Enterprise Peopletools18/4/202317/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
ModificadaMedia (4.9)0.42%—Tigergraph CloudTigergraph Enterprise14/4/202317/6/2026
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph…
ModificadaAlta (8.8)0.83%—Tigergraph CloudTigergraph Enterprise13/4/202317/6/2026
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.
ModificadaMedia (5.5)0.59%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora12/4/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (6.5)0.38%—SAP Netweaver Enterprise Portal11/4/202317/6/2026
In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and integrity.
ModificadaMedia (5.3)0.64%—Github Enterprise Server7/4/202317/6/2026
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. To do so, an attacker would need write access to the repository and be able to correctly guess the target branch before it’s created by the code maintainer. This vulnerability…
ModificadaMedia (5.3)0.46%—Github Enterprise Server7/4/202317/6/2026
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority. To do so, a user had to know the secret gist's URL. This vulnerability affected all versions of GitHub…
ModificadaAlta (7.1)0.25%—Linux KernelRedhat Enterprise Linux29/3/202317/6/2026
A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.
ModificadaAlta (7.8)0.22%—Redhat Device-mapper-multipathRedhat Enterprise Linux29/3/202317/6/2026
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue…
ModificadaAlta (7.8)0.31%—QemuRedhat Enterprise LinuxFedoraproject Fedora29/3/202317/6/2026
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.
ModificadaCrítica (9.1)3.4%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+429/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation…