Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 0.38% | — | Linuxfoundation Dragonfly | 17/9/2025 | 17/6/2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Manager can create, delete, and modify jobs, and create preheat jobs. An… | |
| Aplazada | Baja (3.1) | 0.17% | — | Linuxfoundation LibocppAI | 15/9/2025 | 17/6/2026 | libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation. | |
| Analizada | Alta (7.8) | 0.09% | — | Linuxfoundation YoctoGoogle AndroidOpenwrt | 1/9/2025 | 17/6/2026 | In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09989078; Issue ID: MSV-3964. | |
| Analizada | Media (6.8) | 0.12% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+1 | 4/8/2025 | 17/6/2026 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09915215; Issue ID: MSV-3801. | |
| Analizada | Media (5.5) | 0.85% | — | Linuxfoundation Materialx | 1/8/2025 | 17/6/2026 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, nested imports of MaterialX files can lead to a crash via stack memory exhaustion, due to the lack of a limit on the "import chain" depth. When parsing file imports,… | |
| Analizada | Baja (2) | 0.54% | — | Linuxfoundation Materialx | 1/8/2025 | 17/6/2026 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files. An attacker… | |
| Analizada | Baja (2) | 0.48% | — | Linuxfoundation Materialx | 1/8/2025 | 17/6/2026 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files. An attacker… | |
| Analizada | Media (5.5) | 0.63% | — | Linuxfoundation Materialx | 1/8/2025 | 17/6/2026 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack exhaustion. An… | |
| Aplazada | Media (4.1) | 0.32% | — | Linuxfoundation HarborAI | 23/7/2025 | 17/6/2026 | Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and… | |
| Analizada | Alta (8.8) | 0.60% | — | Linuxfoundation Onnx | 22/7/2025 | 17/6/2026 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions. | |
| Analizada | Media (6.5) | 0.14% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt | 8/7/2025 | 17/6/2026 | In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09812521; Issue ID: MSV-3421. | |
| Aplazada | Media (5.7) | 0.21% | — | Redhat Connectivity LinkAILinuxfoundation KuadrantAI | 9/6/2025 | 17/6/2026 | The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak those secrets over HTTP… | |
| Analizada | Media (5.3) | 0.69% | — | Linuxfoundation Docarray | 25/5/2025 | 17/6/2026 | A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/data/torch_dataset.py of the component Web API. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype… | |
| Analizada | Media (4.6) | 0.28% | — | Linuxfoundation Containerd | 21/5/2025 | 17/6/2026 | containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honored. This may cause a… | |
| Analizada | Alta (7.6) | 0.50% | — | Linuxfoundation Containerd | 20/5/2025 | 17/6/2026 | containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify the host file system. The only affected version of containerd is 2.1.0. Other versions of… | |
| Aplazada | Alta (8.2) | 0.47% | — | Linuxfoundation VolcanoAI | 30/4/2025 | 17/6/2026 | Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service or the extender plugin can cause denial of service of the scheduler. This is a privilege escalation, because Volcano… | |
| Modificada | Crítica (9.3) | 2.2% | 💥 PoC | Linuxfoundation Pytorch | 18/4/2025 | 17/6/2026 | PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue… | |
| Analizada | Media (4.8) | 0.33% | — | Linuxfoundation Pytorch | 16/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may… | |
| Analizada | Media (6.8) | 0.12% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+16 | 7/4/2025 | 17/6/2026 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09625423; Issue ID: MSV-3033. | |
| Analizada | Media (4.8) | 0.26% | — | Linuxfoundation Pytorch | 3/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been… | |
| Analizada | Media (4.8) | 0.27% | — | Linuxfoundation Pytorch | 2/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (4.8) | 0.20% | — | Linuxfoundation Pytorch | 31/3/2025 | 17/6/2026 | A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be… |