Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

3145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)5.5%⚠ Explotación activa💥 ExploitNetapp H300s FirmwareNetapp H410c FirmwareNetapp H410s FirmwareNetapp H500s Firmware+233/3/202217/6/2026
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
ModificadaAlta (7)0.43%—Linux KernelRedhat 3scale API ManagementRedhat Build OF QuarkusRedhat Codeready Linux Builder EUS+283/3/202217/6/2026
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
ModificadaAlta (8.8)74%💥 PoCSambaDebian LinuxCanonical Ubuntu LinuxSynology Diskstation Manager+1921/2/202217/6/2026
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially…
ModificadaAlta (7.5)2.0%—Port389 389-ds-baseRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR Power BIG Endian+418/2/202217/6/2026
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
ModificadaAlta (7.2)1.7%—SambaDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1318/2/202217/6/2026
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total…
ModificadaAlta (8.1)1.6%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2118/2/202217/6/2026
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
ModificadaMedia (5.9)1.8%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2018/2/202217/6/2026
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
ModificadaAlta (7.8)0.19%—DogtagpkiFedoraproject FedoraOracle LinuxRedhat Enterprise Linux+816/2/202217/6/2026
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this…
AnalizadaAlta (7.8)94%⚠ Explotación activa💥 ExploitPolkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2628/1/202215/8/2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends…
ModificadaAlta (8.8)2.5%—Fedoraproject SssdRedhat VirtualizationRedhat Virtualization HostRedhat Enterprise Linux+423/12/202117/6/2026
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this…
ModificadaAlta (7.8)0.56%—X.org X ServerFedoraproject FedoraDebian Linux17/12/202117/6/2026
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.57%—X.org X ServerFedoraproject FedoraDebian Linux17/12/202117/6/2026
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.57%—X.org X ServerFedoraproject FedoraDebian Linux17/12/202117/6/2026
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.56%—X.org X ServerFedoraproject FedoraDebian Linux17/12/202117/6/2026
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaMedia (5.6)2.8%—C-ares Project C-aresFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Computer Node+1323/11/202117/6/2026
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system…
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaMedia (6.5)1.2%—NCH Flexiserver25/7/202117/6/2026
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
ModificadaMedia (6.5)1.2%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+927/5/202117/6/2026
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
ModificadaAlta (7)0.31%—X.org X Server26/5/202117/6/2026
A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting to connect to.
ModificadaAlta (7.8)10.0%—Omron Cx-oneOmron Cx-server13/5/202117/6/2026
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)1.1%—X.org X ServerFedoraproject FedoraDebian LinuxRedhat Enterprise Linux26/4/202117/6/2026
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaMedia (6.5)0.84%—HPE Superdome Flex Server Firmware1/4/202117/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following…
ModificadaBaja (3.7)1.6%—Nbdkit Project NbdkitRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Server18/3/202117/6/2026
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and…
ModificadaAlta (8.2)0.60%💥 PoCGNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each…
ModificadaMedia (6.7)1.0%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as…