Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.37% | — | ClaircoreAI | 11/8/2026 | 14/8/2026 | A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service. | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | ClaircoreAI | 20/7/2026 | 21/7/2026 | A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service. | |
| Rechazada | Sin puntuar | — | — | Quay ClaircoreAIRedhat ClairAI | 1/6/2026 | 27/7/2026 | Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is… | |
| Analizada | Alta (7.9) | 0.65% | — | Qnap AI Core | 22/11/2024 | 17/6/2026 | An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core 3.4.1 and later | |
| Modificada | Alta (7.4) | 1.1% | — | Canarymail Canary MailLibmailcore Mailcore2 | 17/2/2021 | 17/6/2026 | core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode. | |
| Modificada | Alta (7.4) | 2.4% | — | Libetpan Project LibetpanLibmailcore Mailcore2Fedoraproject FedoraDebian Linux | 27/7/2020 | 17/6/2026 | LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response… | |
| Modificada | Media (5) | 2.2% | — | Lanai-core | 28/7/2010 | 16/6/2026 | Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function. | |
| Modificada | Media (5) | 1.7% | — | Lanai-core | 28/7/2010 | 16/6/2026 | Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. |