Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

4007 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.35%—Opensuse Cyrus-sasl25/2/202117/6/2026
A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.
ModificadaMedia (4.4)0.25%—Suse Caas Platform11/2/202117/6/2026
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.
ModificadaMedia (4)0.29%—Suse Caas Platform11/2/202117/6/2026
A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.
ModificadaMedia (6.6)0.30%—Opensuse Openldap211/2/202117/6/2026
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise…
ModificadaMedia (5.4)0.74%—Opensuse Open Build Service11/2/202117/6/2026
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.
ModificadaMedia (6.5)1.2%—Intel ConnmanDebian LinuxOpensuse Leap9/2/202117/6/2026
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
ModificadaAlta (8.8)1.3%—Intel ConnmanDebian LinuxOpensuse Leap9/2/202117/6/2026
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
ModificadaMedia (5.7)0.56%—Intel Ax201 FirmwareIntel Ax200 FirmwareIntel AC 9560 FirmwareIntel AC 9462 Firmware+1123/11/202017/6/2026
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitSaltstack SaltDebian LinuxFedoraproject FedoraOpensuse Leap6/11/202017/6/2026
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
ModificadaMedia (6.3)0.42%—Sddm Project SddmOpensuse LeapDebian LinuxFedoraproject Fedora4/11/202017/6/2026
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example,…
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora3/11/202017/6/2026
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
ModificadaCrítica (9.6)2.4%—Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux3/11/202017/6/2026
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
AnalizadaAlta (8.8)48%⚠ Explotación activaCefsharpGoogle ChromeMicrosoft EdgeMicrosoft Edge Chromium+43/11/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.2%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+13/11/202017/6/2026
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.
ModificadaAlta (7.8)0.27%—Google ChromeOpensuse Backports SLEDebian LinuxOpensuse Leap3/11/202017/6/2026
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+13/11/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux+13/11/202017/6/2026
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+13/11/202017/6/2026
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE3/11/202017/6/2026
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject FedoraOpensuse Backports SLEDebian Linux3/11/202017/6/2026
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxOpensuse Backports SLEFedoraproject Fedora3/11/202017/6/2026
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.6%—Google ChromeFedoraproject FedoraOpensuse Backports SLEDebian Linux3/11/202017/6/2026
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
AnalizadaCrítica (9.6)64%⚠ Explotación activa💥 PoCGoogle ChromeFreetypeDebian LinuxFedoraproject Fedora+23/11/202017/6/2026
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeDebian LinuxOpensuse Backports SLEFedoraproject Fedora3/11/202017/6/2026
Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEFedoraproject FedoraDebian Linux3/11/202017/6/2026
Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.