Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

366 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.79%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1418/11/201917/6/2026
Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
ModificadaMedia (4.7)0.45%—Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+1318/11/201917/6/2026
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b.
ModificadaAlta (7.5)3.3%—Linux KernelCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp AFF Baseboard Management Controller+1118/11/201917/6/2026
A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy_from_iter_full() failures, aka CID-bbe692e349e2.
ModificadaAlta (7.5)5.4%—Linux KernelOracle Sd-wan EdgeCanonical Ubuntu LinuxDebian Linux+1418/11/201917/6/2026
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
ModificadaAlta (7.5)5.1%—Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+1318/11/201917/6/2026
A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
ModificadaAlta (7.5)4.0%—Linux KernelNetapp Active IQ Unified ManagerNetapp AFF Baseboard Management ControllerNetapp Cloud Backup+1118/11/201917/6/2026
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762.
ModificadaMedia (5.5)0.28%—Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+114/11/201917/6/2026
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.28%—Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+114/11/201917/6/2026
Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.30%—Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+114/11/201917/6/2026
Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (4.4)0.35%—Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+114/11/201917/6/2026
Buffer overflow in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6618 (DCH) or 21.20.x.5077 (aka15.45.5077) may allow a privileged user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.35%—Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+114/11/201917/6/2026
Pointer corruption in the Unified Shader Compiler in Intel(R) Graphics Drivers before 10.18.14.5074 (aka 15.36.x.5074) may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.31%—Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+114/11/201917/6/2026
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.36%—Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage14/11/201917/6/2026
Memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver before 26.20.100.6813 (DCH) or 26.20.100.6812 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)3.4%—Linux KernelOpensuse LeapRedhat Enterprise LinuxNetapp Active IQ Unified Manager+137/11/201917/6/2026
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other…
ModificadaAlta (7)0.99%💥 PoCLinux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+144/11/201917/6/2026
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this…
AnalizadaAlta (7.8)72%⚠ Explotación activa💥 ExploitGoogle AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+7311/10/201917/6/2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing…
ModificadaAlta (7.5)3.5%—Linux KernelOpensuse LeapNetapp AFF A700s FirmwareNetapp H300s Firmware+1330/9/201917/6/2026
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
ModificadaMedia (5.5)0.25%—Jenkins Neuvector Vulnerability Scanner25/9/201917/6/2026
Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaAlta (7.8)0.91%—Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Compute Node EUS+3520/9/201917/6/2026
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
ModificadaAlta (7.8)0.87%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+3020/9/201917/6/2026
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
ModificadaMedia (6.5)1.4%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
ModificadaMedia (5.3)1.8%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
ModificadaMedia (5.3)1.8%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
ModificadaMedia (5.3)1.8%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
ModificadaMedia (5.3)2.0%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.