Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.21%—GNU TARAIUbuntuAIDebianAICentosAI17/6/202622/6/2026
The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extraction path traversal was…
Pendiente de análisisAlta (7.5)0.53%—CentosdrAI15/4/202617/6/2026
CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
AplazadaAlta (8.7)0.36%—Radiflow Isap Smart CollectorAICentos 7AI9/7/202517/6/2026
The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product.
ModificadaCrítica (9.8)1.6%—Tencentos-tiny3/5/202217/6/2026
TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
ModificadaMedia (6.1)0.20%—Gnome-shellCentos Stream18/2/202217/6/2026
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked…
ModificadaCrítica (9.8)8.1%—Centos-webpanel Centos WEB Panel28/7/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_stop parameter, the process does not properly…
ModificadaAlta (7.8)0.90%—Projectatomic BubblewrapDebian LinuxArchlinux Arch LinuxCentos31/3/202017/6/2026
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects…
ModificadaMedia (6.5)2.2%—Centos-webpanel Centos WEB Panel21/8/201917/6/2026
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.
ModificadaMedia (6.5)1.9%—Centos-webpanel Centos WEB Panel21/8/201917/6/2026
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.
ModificadaAlta (8.8)2.8%—Centos-webpanel Centos WEB Panel26/7/201917/6/2026
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.
ModificadaMedia (4.8)2.8%—Centos-webpanel Centos WEB Panel18/4/201917/6/2026
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By changing the email ID to any XSS Payload and clicking on Save Changes, the XSS Payload will execute.
ModificadaMedia (4.8)2.3%—Centos-webpanel Centos WEB Panel3/4/201917/6/2026
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.
AnalizadaAlta (7.8)11%⚠ Explotación activaCentosRedhat Enterprise LinuxLinux Kernel5/10/201717/6/2026
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but…
ModificadaMedia (6.8)0.28%—EMC Documentum Content ServerCentos2/2/201216/6/2026
Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local users to obtain "highest super user privileges" by leveraging system administrator privileges.
ModificadaMedia (4.9)0.42%—Fedoraproject Fedora CoreRedhat Enterprise LinuxOracle LinuxCentos+518/12/200716/6/2026
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.