Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.16% | — | Motorola OTA Update ApplicationAI | 4/3/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI. | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Update Package Framework | 1/3/2024 | 17/6/2026 | Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin. | |
| Analizada | Crítica (9.8) | 0.57% | — | Prestashop Import/update Bulk Product | 27/2/2024 | 17/6/2026 | In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Modificada | Alta (7.3) | 0.32% | — | Fedoraproject UnboundRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+15 | 15/2/2024 | 6/8/2026 | A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to… | |
| Modificada | Alta (7.8) | 0.19% | — | Intel ONE Boot Flash Update | 14/2/2024 | 17/6/2026 | Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.31% | — | Redhat 389 Directory ServerRedhat Directory ServerFedoraproject FedoraRedhat Enterprise Linux+9 | 12/2/2024 | 17/6/2026 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. | |
| Modificada | Alta (7.8) | 1.2% | — | X.org X ServerX.org XwaylandFedoraproject FedoraRedhat Enterprise Linux+4 | 9/2/2024 | 17/6/2026 | An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution… | |
| Modificada | Alta (7.5) | 1.5% | — | Linux KernelRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+13 | 7/2/2024 | 17/6/2026 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service. | |
| Modificada | Alta (7.5) | 1.5% | — | Linux KernelRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+12 | 7/2/2024 | 17/6/2026 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUS+13 | 7/2/2024 | 17/6/2026 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a denial of service. | |
| Modificada | Alta (7.1) | 0.17% | — | Dell Update Package Framework | 6/2/2024 | 17/6/2026 | DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+1 | 5/2/2024 | 17/6/2026 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Analizada | Alta (7.5) | 1.1% | — | Redhat Enterprise LinuxRedhat Update InfrastructureM2crypto Project M2crypto | 5/2/2024 | 16/9/2026 | A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Modificada | Media (5.9) | 1.2% | — | Opensc Project OpenscRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+7 | 31/1/2024 | 17/6/2026 | A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. | |
| Modificada | Media (6.5) | 0.57% | — | FreeipaFedoraproject FedoraRedhat Codeready Linux BuilderRedhat Enterprise Linux+17 | 10/1/2024 | 17/6/2026 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration… | |
| Analizada | Media (6.7) | 0.84% | — | Redhat Codeready Linux Builder FOR EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUSRedhat Codeready Linux Builder FOR Power Little Endian EUSRedhat Enterprise Linux+18 | 2/1/2024 | 17/6/2026 | A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with… | |
| Modificada | Alta (7.8) | 0.95% | — | Kylinos Kylin-system-updater | 25/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected is an unknown function of the file /usr/share/kylin-system-updater/SystemUpdater/UpgradeStrategiesDbus.py of the component com.kylin.systemupgrade Service. The manipulation of the argument… | |
| Modificada | Alta (7.1) | 0.53% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+1 | 8/12/2023 | 17/6/2026 | An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information. | |
| Modificada | Crítica (9.8) | 0.77% | — | Myprestamodules Updateproducts | 27/11/2023 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel ONE Boot Flash Update | 14/11/2023 | 17/6/2026 | Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel ONE Boot Flash Update | 14/11/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel ONE Boot Flash Update | 14/11/2023 | 17/6/2026 | Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.31% | — | WP Browserupdate | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.4.1 versions. | |
| Modificada | Alta (7.8) | 0.32% | — | Lenovo System Update | 8/11/2023 | 17/6/2026 | An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.27% | — | Redhat Insights-clientRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Desktop+15 | 1/11/2023 | 17/6/2026 | A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could… |