Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.41%—Relative Synchrony17/10/202317/6/2026
Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties…
ModificadaMedia (6)0.48%—Tuxfamily ChronyFedoraproject FedoraCanonical Ubuntu Linux24/8/202017/6/2026
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows…
ModificadaMedia (6.5)1.7%—Tuxfamily Chrony9/12/201917/6/2026
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
ModificadaAlta (7.5)4.2%—Chrony Project ChronyDebian LinuxFedoraproject Fedora15/11/201917/6/2026
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
ModificadaAlta (7.5)0.76%—Dell EMC Vplex Geosynchrony11/9/201817/6/2026
Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could read from VPN configuration files on and potentially author a MITM attack on the VPN traffic.
ModificadaAlta (8.1)3.0%—Tuxfamily Chrony26/1/201617/6/2026
chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
ModificadaAlta (8.4)0.54%—EMC Vplex Geosynchrony28/12/201517/6/2026
EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privileges by leveraging a login session.
ModificadaBaja (2.1)0.51%—EMC Vplex Geosynchrony18/11/201517/6/2026
The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file.
ModificadaMedia (6.5)2.9%—Debian LinuxTuxfamily Chrony16/4/201517/6/2026
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
ModificadaMedia (6.5)3.4%—Tuxfamily ChronyDebian Linux16/4/201517/6/2026
Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
ModificadaAlta (7.5)1.2%—EMC Vplex Geosynchrony1/4/201417/6/2026
Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaMedia (6)0.96%—EMC Vplex Geosynchrony1/4/201417/6/2026
EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
ModificadaAlta (7.7)0.85%—EMC Vplex Geosynchrony1/4/201417/6/2026
The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation.
ModificadaAlta (9)4.5%—EMC Vplex Geosynchrony1/4/201417/6/2026
Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.
ModificadaMedia (5)3.1%—Tuxfamily Chrony5/11/201316/6/2026
cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an invalid subnet in a RPY_SUBNETS_ACCESSED command to the handle_subnets_accessed function or (2) a RPY_CLIENT_ACCESSES command to the handle_client_accesses function when…
ModificadaMedia (5)3.2%—Tuxfamily Chrony5/11/201316/6/2026
Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (crash) via a crafted (1) REQ_SUBNETS_ACCESSED or (2) REQ_CLIENT_ACCESSES command request to the PKL_CommandLength function or crafted (3) RPY_SUBNETS_ACCESSED, (4) RPY_CLIENT_ACCESSES, (5)…
ModificadaMedia (4.9)0.34%—EMC GeosynchronyEMC Vplex GEOEMC Vplex LocalEMC Vplex Metro1/10/201316/6/2026
EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file.
ModificadaMedia (5)2.7%—Tuxfamily Chrony8/2/201016/6/2026
chronyd in Chrony before 1.23.1, and possibly 1.24-pre1, generates a syslog message for each unauthorized cmdmon packet, which allows remote attackers to cause a denial of service (disk consumption) via a large number of invalid packets.
ModificadaMedia (5)2.7%—Tuxfamily Chrony8/2/201016/6/2026
The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.
ModificadaMedia (5)1.7%—Tuxfamily Chrony8/2/201016/6/2026
The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a spoofed cmdmon packet that triggers a continuous exchange of NOHOSTACCESS messages between two daemons, a related issue to…