Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.26% | — | Canonical Netplan | 7/6/2024 | 17/6/2026 | netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected. | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing | |
| Modificada | Alta (7.8) | 0.23% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | Apport does not disable python crash handler before entering chroot | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to consume RAM in the Apport process | |
| Modificada | Alta (7.1) | 0.21% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to create arbitrary tcp dbus connections | |
| Modificada | Media (5.5) | 0.25% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to fill up apport.log | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack | |
| Analizada | Alta (7.8) | 0.23% | — | Canonical ApportCanonical Ubuntu Linux | 3/6/2024 | 17/6/2026 | Apport can be tricked into connecting to arbitrary sockets as the root user | |
| Analizada | Alta (8.4) | 0.28% | — | Canonical Subiquity | 3/6/2024 | 17/6/2026 | Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions | |
| Analizada | Alta (7.8) | 0.38% | 💥 PoC | Canonical ApportCanonical Ubuntu Linux | 3/6/2024 | 17/6/2026 | There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root. | |
| Analizada | Alta (8.1) | 0.83% | — | Canonical Snapd | 31/5/2024 | 17/6/2026 | The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would… | |
| Analizada | Media (6.5) | 0.20% | — | Canonical Pebble | 4/4/2024 | 17/6/2026 | It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Canon Satera Mf740cAICanon Satera Mf640cAICanon Satera Lbp660cAICanon Satera Lbp620cAI+22 | 11/3/2024 | 17/6/2026 | Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C… | |
| Analizada | Alta (8.8) | 0.55% | — | Dalibo Anonymizer | 8/3/2024 | 17/6/2026 | PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the… | |
| Analizada | Alta (7.5) | 0.46% | — | Dalibo Anonymizer | 8/3/2024 | 17/6/2026 | PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. PostgreSQL Anonymizer enables users to set security labels on tables to mask specified columns. There is a flaw that allows complex expressions to be provided… | |
| Analizada | Media (6.7) | 0.24% | — | Canonical LXDTianocore Edk2 | 14/2/2024 | 17/6/2026 | An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot. | |
| Analizada | Media (6.7) | 0.26% | — | Canonical LXDTianocore Edk2Debian Linux | 14/2/2024 | 17/6/2026 | An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon I-sensys Mf754cdw FirmwareCanon I-sensys X C1333if FirmwareCanon Mf755cdw FirmwareCanon Mf753cdw Firmware+3 | 6/2/2024 | 17/6/2026 | Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in… | |
| Modificada | Crítica (9.8) | 1.5% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera… | |
| Modificada | Crítica (9.8) | 1.4% | — | Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+25 | 6/2/2024 | 17/6/2026 | Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold… | |
| Modificada | Alta (7.5) | 0.61% | — | Cayenne Anonymous Restricted Content | 3/2/2024 | 17/6/2026 | The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient restrictions through the REST API on the posts/pages that protections are being place on. This makes it possible for unauthenticated attackers to access… |