Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
10.007 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar In w7090p_tuner_write_serpar, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on msg[0].buf would be… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix uninited ptr deref in block/scsi layout The error occurs on the third attempt to encode extents. When function ext_tree_prepare_commit() reallocates a larger buffer to retry encoding extents, the "layoutupdate_pages" page array is… | |
| Modificada | Media (4.7) | 0.13% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syzbot reports a use-after-free in comedi in the below link, which is due to comedi gladly removing the allocated async area even though poll requests are still active on the wait_queue_head inside of it.… | |
| Modificada | Alta (7.8) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imageblit This issue triggers when a userspace program does an ioctl FBIOPUT_CON2FBMAP by passing console number and frame buffer number. Ideally this maps console to frame buffer and updates the screen… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: use old 'nbands' while purging unused classes Shuang reported sch_ets test-case [1] crashing in ets_class_qlen_notify() after recent changes from Lion [2]. The problem is: in ets_qdisc_change() we purge unused DWRR queues; the value of… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix panic during namespace deletion with VF The existing code move the VF NIC to new namespace when NETDEV_REGISTER is received on netvsc NIC. During deletion of the namespace, default_device_exit_batch() >> default_device_exit_net() is… | |
| Modificada | Media (4.7) | 0.13% | — | Linux KernelDebian Linux | 4/9/2025 | 14/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() Memory hot remove unmaps and tears down various kernel page table regions as required. The ptdump code can race with concurrent modifications of the kernel page tables. When leaf entries… | |
| Modificada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 4/9/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], requiring at least 4… | |
| Modificada | Alta (7.1) | 0.17% | — | Linux KernelDebian Linux | 4/9/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler processes a variable number of properties sent by the firmware. The number of properties is indicated by the firmware and used to iterate over the… | |
| Modificada | Alta (7.1) | 0.17% | — | Linux KernelDebian Linux | 30/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in dnode page As Jiaming Zhang reported: The root cause is in the corrupted image, there is a dnode has the same node id w/ its inode, so during f2fs_get_dnode_of_data(), it tries to access block address in… | |
| Modificada | Alta (7.8) | 0.33% | — | Linux KernelDebian Linux | 28/8/2025 | 19/8/2026 | In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling from async If we're not doing async, the handling is much simpler. There's no reference counting, we just need to wait for the completion to wake us up and return its result. We should preferably also… | |
| Modificada | Alta (7.8) | 0.40% | 💥 PoC | Linux KernelDebian Linux | 26/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel cmdline While the kernel command line is considered trusted in most environments, avoid writing 1 byte past the end of "acpiid" if the "str" argument is maximum length. | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: qup: jump out of the loop in case of timeout Original logic only sets the return value but doesn't jump out of the loop if the bus is kept active by a client. This is not expected. A malicious or buggy i2c client can hang the kernel in this case… | |
| Modificada | Alta (7.1) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() `cpu_switch_to()` and `call_on_irq_stack()` manipulate SP to change to different stacks along with the Shadow Call Stack if it is enabled. Those two stack changes cannot be done atomically… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix NULL dereference on unbind due to stale coupling data Failing to reset coupling_desc.n_coupled after freeing coupled_rdevs can lead to NULL pointer dereference when regulators are accessed post-unbind. This can happen during… | |
| Analizada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix use-after-free in AARP proxy probe The AARP proxy‐probe routine (aarp_proxy_probe_network) sends a probe, releases the aarp_lock, sleeps, then re-acquires the lock. During that window an expire timer thread (__aarp_expire_timer)… | |
| Analizada | Media (5.5) | 0.15% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: can: netlink: can_changelink(): fix NULL pointer deref of struct can_priv::do_set_mode Andrei Lalaev reported a NULL pointer deref when a CAN device is restarted from Bus Off and the driver does not implement the struct can_priv::do_set_mode callback.… | |
| Analizada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() Add check for the return value of devm_kmemdup() to prevent potential null pointer dereference. | |
| Analizada | Media (5.5) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject invalid file types when reading inodes To prevent inodes with invalid file types from tripping through the vfs and causing malfunctions or assertion failures, add a missing sanity check when reading an inode from a block device. If the… | |
| Modificada | Alta (7.8) | 0.17% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al Check pde->proc_ops->proc_lseek directly may cause UAF in rmmod scenario. It's a gap in proc_reg_open() after commit 654b33ada4ab("proc: fix UAF in proc_get_inode()").… | |
| Modificada | Alta (7.1) | 0.18% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - touch /mnt/f2fs/file… | |
| Analizada | Media (5.5) | 0.13% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: remove mutex_lock check in hfsplus_free_extents Syzbot reported an issue in hfsplus filesystem: To avoid deadlock, Commit 31651c607151 ("hfsplus: avoid deadlock on file truncation") unlock extree before hfsplus_free_extents(), and add check… | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Check device memory pointer before usage Add a NULL check before accessing device memory to prevent a crash if dev->dm allocation in mlx5_init_once() fails. | |
| Analizada | Media (5.5) | 0.16% | — | Linux KernelDebian Linux | 22/8/2025 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reject TDLS operations when station is not associated syzbot triggered a WARN in ieee80211_tdls_oper() by sending NL80211_TDLS_ENABLE_LINK immediately after NL80211_CMD_CONNECT, before association completed and without prior TDLS… | |
| Modificada | Media (5.5) | 0.18% | — | Linux KernelDebian Linux | 22/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nfacct: don't assume acct name is null-terminated nfnl_acct_find_get() handles non-null input, but the error printk relied on its presence. |