Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitSaltstack SaltDebian LinuxFedoraproject FedoraOpensuse Leap6/11/202017/6/2026
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
ModificadaMedia (6.3)0.42%—Sddm Project SddmOpensuse LeapDebian LinuxFedoraproject Fedora4/11/202017/6/2026
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example,…
ModificadaCrítica (9.6)2.4%—Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux3/11/202017/6/2026
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
AnalizadaAlta (8.8)48%⚠ Explotación activaCefsharpGoogle ChromeMicrosoft EdgeMicrosoft Edge Chromium+43/11/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.2%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+13/11/202017/6/2026
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
ModificadaAlta (7.8)0.27%—Google ChromeOpensuse Backports SLEDebian LinuxOpensuse Leap3/11/202017/6/2026
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+13/11/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux+13/11/202017/6/2026
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+13/11/202017/6/2026
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (5.5)0.62%—SambaOpensuse LeapFedoraproject FedoraDebian Linux29/10/202017/6/2026
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
ModificadaMedia (5.5)0.41%—Linux KernelDebian LinuxOpensuse LeapXEN22/10/202017/6/2026
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.
ModificadaAlta (7)0.26%—XENFedoraproject FedoraOpensuse LeapDebian Linux22/10/202017/6/2026
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
ModificadaAlta (7.8)0.34%—XENOpensuse LeapDebian LinuxFedoraproject Fedora22/10/202017/6/2026
An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled.
ModificadaAlta (7.8)0.25%—XENOpensuse LeapFedoraproject FedoraDebian Linux22/10/202017/6/2026
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated.
ModificadaCrítica (9.8)2.7%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+122/10/202017/6/2026
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4,…
ModificadaBaja (3.3)1.5%—ImagemagickDebian LinuxOpensuse Leap22/10/202017/6/2026
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
AnalizadaMedia (5.3)3.2%—Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+1521/10/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can…
AnalizadaBaja (3.1)2.7%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.7)2.2%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.1)2.5%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaMedia (4.2)2.2%—Oracle OpenjdkOracle JDKOracle JREDebian Linux+1521/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.7)2.3%—Oracle OpenjdkOracle JDKOracle JREDebian Linux+1221/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.7)2.3%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1321/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
AnalizadaBaja (3.7)3.8%—Oracle OpenjdkOracle JDKOracle JREDebian Linux+1521/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (7.5)6.5%—Powerdns RecursorOpensuse Backports SLEOpensuse Leap16/10/202017/6/2026
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of…