Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

4419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.26%—Canonical Netplan7/6/202417/6/2026
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
ModificadaAlta (7.8)0.23%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
Apport does not disable python crash handler before entering chroot
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to consume RAM in the Apport process
ModificadaAlta (7.1)0.21%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to create arbitrary tcp dbus connections
ModificadaMedia (5.5)0.25%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to fill up apport.log
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
AnalizadaAlta (7.8)0.23%—Canonical ApportCanonical Ubuntu Linux3/6/202417/6/2026
Apport can be tricked into connecting to arbitrary sockets as the root user
AnalizadaAlta (8.4)0.28%—Canonical Subiquity3/6/202417/6/2026
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
AnalizadaAlta (7.8)0.38%💥 PoCCanonical ApportCanonical Ubuntu Linux3/6/202417/6/2026
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
AnalizadaAlta (8.1)0.83%—Canonical Snapd31/5/202417/6/2026
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would…
AnalizadaMedia (6.5)0.20%—Canonical Pebble4/4/202417/6/2026
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.
AplazadaCrítica (9.8)0.81%—Canon Satera Mf740cAICanon Satera Mf640cAICanon Satera Lbp660cAICanon Satera Lbp620cAI+2211/3/202417/6/2026
Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C…
AnalizadaAlta (8.8)0.55%—Dalibo Anonymizer8/3/202417/6/2026
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the…
AnalizadaAlta (7.5)0.46%—Dalibo Anonymizer8/3/202417/6/2026
PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. PostgreSQL Anonymizer enables users to set security labels on tables to mask specified columns. There is a flaw that allows complex expressions to be provided…
AnalizadaMedia (6.7)0.24%—Canonical LXDTianocore Edk214/2/202417/6/2026
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
AnalizadaMedia (6.7)0.26%—Canonical LXDTianocore Edk2Debian Linux14/2/202417/6/2026
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
ModificadaCrítica (9.8)1.4%—Canon I-sensys Mf754cdw FirmwareCanon I-sensys X C1333if FirmwareCanon Mf755cdw FirmwareCanon Mf753cdw Firmware+36/2/202417/6/2026
Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in…
ModificadaCrítica (9.8)1.5%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.…
ModificadaCrítica (9.8)1.5%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera…
ModificadaCrítica (9.8)1.4%—Canon Mf755cdw FirmwareCanon Mf753cdw FirmwareCanon Mf751cdw FirmwareCanon Lbp674c Firmware+256/2/202417/6/2026
Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold…
ModificadaAlta (7.5)0.61%—Cayenne Anonymous Restricted Content3/2/202417/6/2026
The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient restrictions through the REST API on the posts/pages that protections are being place on. This makes it possible for unauthenticated attackers to access…