Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Saltstack SaltDebian LinuxFedoraproject FedoraOpensuse Leap | 6/11/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. | |
| Modificada | Media (6.3) | 0.42% | — | Sddm Project SddmOpensuse LeapDebian LinuxFedoraproject Fedora | 4/11/2020 | 17/6/2026 | An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example,… | |
| Modificada | Crítica (9.6) | 2.4% | — | Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux | 3/11/2020 | 17/6/2026 | Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| Analizada | Alta (8.8) | 48% | ⚠ Explotación activa | CefsharpGoogle ChromeMicrosoft EdgeMicrosoft Edge Chromium+4 | 3/11/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.2% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 3/11/2020 | 17/6/2026 | Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet. | |
| Modificada | Alta (7.8) | 0.27% | — | Google ChromeOpensuse Backports SLEDebian LinuxOpensuse Leap | 3/11/2020 | 17/6/2026 | Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 3/11/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 3/11/2020 | 17/6/2026 | Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 3/11/2020 | 17/6/2026 | Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (5.5) | 0.62% | — | SambaOpensuse LeapFedoraproject FedoraDebian Linux | 29/10/2020 | 17/6/2026 | A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service. | |
| Modificada | Media (5.5) | 0.41% | — | Linux KernelDebian LinuxOpensuse LeapXEN | 22/10/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271. | |
| Modificada | Alta (7) | 0.26% | — | XENFedoraproject FedoraOpensuse LeapDebian Linux | 22/10/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages. | |
| Modificada | Alta (7.8) | 0.34% | — | XENOpensuse LeapDebian LinuxFedoraproject Fedora | 22/10/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled. | |
| Modificada | Alta (7.8) | 0.25% | — | XENOpensuse LeapFedoraproject FedoraDebian Linux | 22/10/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated. | |
| Modificada | Crítica (9.8) | 2.7% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+1 | 22/10/2020 | 17/6/2026 | Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4,… | |
| Modificada | Baja (3.3) | 1.5% | — | ImagemagickDebian LinuxOpensuse Leap | 22/10/2020 | 17/6/2026 | ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service. | |
| Analizada | Media (5.3) | 3.2% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Analizada | Baja (3.1) | 2.7% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.1) | 2.5% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Media (4.2) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.3% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+12 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.3% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+13 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Analizada | Baja (3.7) | 3.8% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 6.5% | — | Powerdns RecursorOpensuse Backports SLEOpensuse Leap | 16/10/2020 | 17/6/2026 | An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of… |