Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.41% | — | Relative Synchrony | 17/10/2023 | 17/6/2026 | Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties… | |
| Modificada | Media (6) | 0.48% | — | Tuxfamily ChronyFedoraproject FedoraCanonical Ubuntu Linux | 24/8/2020 | 17/6/2026 | A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows… | |
| Modificada | Media (6.5) | 1.7% | — | Tuxfamily Chrony | 9/12/2019 | 17/6/2026 | chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets. | |
| Modificada | Alta (7.5) | 4.2% | — | Chrony Project ChronyDebian LinuxFedoraproject Fedora | 15/11/2019 | 17/6/2026 | Chrony before 1.29.1 has traffic amplification in cmdmon protocol | |
| Modificada | Alta (7.5) | 0.76% | — | Dell EMC Vplex Geosynchrony | 11/9/2018 | 17/6/2026 | Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could read from VPN configuration files on and potentially author a MITM attack on the VPN traffic. | |
| Modificada | Alta (8.1) | 3.0% | — | Tuxfamily Chrony | 26/1/2016 | 17/6/2026 | chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key." | |
| Modificada | Alta (8.4) | 0.54% | — | EMC Vplex Geosynchrony | 28/12/2015 | 17/6/2026 | EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privileges by leveraging a login session. | |
| Modificada | Baja (2.1) | 0.51% | — | EMC Vplex Geosynchrony | 18/11/2015 | 17/6/2026 | The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Media (6.5) | 2.9% | — | Debian LinuxTuxfamily Chrony | 16/4/2015 | 17/6/2026 | chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests. | |
| Modificada | Media (6.5) | 3.4% | — | Tuxfamily ChronyDebian Linux | 16/4/2015 | 17/6/2026 | Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder. | |
| Modificada | Alta (7.5) | 1.2% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (6) | 0.96% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Alta (7.7) | 0.85% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation. | |
| Modificada | Alta (9) | 4.5% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 3.1% | — | Tuxfamily Chrony | 5/11/2013 | 16/6/2026 | cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when… | |
| Modificada | Media (5) | 3.2% | — | Tuxfamily Chrony | 5/11/2013 | 16/6/2026 | Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (crash) via a crafted (1) REQ_SUBNETS_ACCESSED or (2) REQ_CLIENT_ACCESSES command request to the PKL_CommandLength function or crafted (3) RPY_SUBNETS_ACCESSED, (4) RPY_CLIENT_ACCESSES, (5)… | |
| Modificada | Media (4.9) | 0.34% | — | EMC GeosynchronyEMC Vplex GEOEMC Vplex LocalEMC Vplex Metro | 1/10/2013 | 16/6/2026 | EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file. | |
| Modificada | Media (5) | 2.7% | — | Tuxfamily Chrony | 8/2/2010 | 16/6/2026 | chronyd in Chrony before 1.23.1, and possibly 1.24-pre1, generates a syslog message for each unauthorized cmdmon packet, which allows remote attackers to cause a denial of service (disk consumption) via a large number of invalid packets. | |
| Modificada | Media (5) | 2.7% | — | Tuxfamily Chrony | 8/2/2010 | 16/6/2026 | The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets. | |
| Modificada | Media (5) | 1.7% | — | Tuxfamily Chrony | 8/2/2010 | 16/6/2026 | The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a spoofed cmdmon packet that triggers a continuous exchange of NOHOSTACCESS messages between two daemons, a related issue to… |