Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.0% | 💥 PoC | Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+6 | 19/8/2020 | 17/6/2026 | A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. | |
| Modificada | Baja (3.7) | 5.3% | — | Linux KernelOpensuse LeapFedoraproject FedoraDebian Linux+11 | 30/7/2020 | 17/6/2026 | The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c. | |
| Analizada | Alta (7.4) | 13% | 💥 PoC | Openbsd OpensshNetapp A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+5 | 24/7/2020 | 17/6/2026 | scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking… | |
| Modificada | Media (5.9) | 2.1% | — | Openbsd OpensshNetapp AFF A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+5 | 29/6/2020 | 17/6/2026 | The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6… | |
| Modificada | Media (4.4) | 0.62% | — | Linux KernelOpensuse LeapCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+15 | 12/6/2020 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. | |
| Modificada | Alta (7.4) | 3.3% | — | NTPNetapp Cloud BackupNetapp Clustered Data OntapNetapp Data Ontap+21 | 4/6/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query… | |
| Modificada | Media (6.7) | 0.46% | — | Systemd Project SystemdNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeFedoraproject Fedora | 3/6/2020 | 17/6/2026 | systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082. | |
| Modificada | Media (6.5) | 5.2% | — | Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+20 | 18/5/2020 | 17/6/2026 | gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4. | |
| Modificada | Media (5.3) | 0.40% | — | Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+21 | 15/5/2020 | 17/6/2026 | The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+20 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails. | |
| Modificada | Media (6.7) | 0.59% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040. | |
| Modificada | Media (5.5) | 0.65% | — | Linux KernelDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8. | |
| Modificada | Media (6.4) | 0.36% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux+18 | 8/5/2020 | 17/6/2026 | There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it… | |
| Modificada | Media (6.7) | 0.71% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud BackupNetapp HCI Baseboard Management Controller+4 | 5/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation. | |
| Modificada | Alta (7.8) | 0.45% | — | Linux KernelOpensuse LeapDebian LinuxNetapp Active IQ Unified Manager+18 | 5/5/2020 | 17/6/2026 | An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea. | |
| Modificada | Alta (7) | 0.53% | — | GNU GlibcCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp HCI Management Node+4 | 30/4/2020 | 17/6/2026 | A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that,… | |
| Modificada | Media (6.7) | 0.38% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud BackupNetapp HCI Baseboard Management Controller+5 | 29/4/2020 | 17/6/2026 | An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages. | |
| Modificada | Alta (7) | 0.40% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+19 | 29/4/2020 | 17/6/2026 | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur. | |
| Modificada | Alta (7.5) | 2.1% | — | NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+13 | 17/4/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp. | |
| Modificada | Media (5.5) | 0.45% | — | Canonical Ubuntu LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management NodeNetapp Steelstore Cloud Integrated Storage+28 | 10/4/2020 | 17/6/2026 | The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this… | |
| Modificada | Alta (7.8) | 6.0% | 💥 PoC | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+23 | 2/4/2020 | 17/6/2026 | In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was… | |
| Modificada | Media (5.5) | 0.76% | — | GNU GlibcFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+7 | 4/3/2020 | 17/6/2026 | The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to… | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+5 | 25/2/2020 | 17/6/2026 | An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause… | |
| Modificada | Alta (7.1) | 0.76% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+8 | 25/2/2020 | 17/6/2026 | An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2. | |
| Modificada | Media (5.5) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+6 | 14/2/2020 | 17/6/2026 | ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. |