Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
30.426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | — | — | I18next-http-backendAI | 6/10/2026 | 6/10/2026 | i18next-http-backend is a backend layer for i18next that loads translation resources in Node.js, browsers, and Deno. Prior to 4.0.2, attacker-controlled language or namespace values interpolated into a custom loadPath or addPath that begins directly with {{lng}} or {{ns}} can make colon-based input become an absolute… | |
| Aplazada | Media (6.9) | — | — | Mooncake StoreAI | 6/10/2026 | 6/10/2026 | Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at… | |
| Aplazada | Alta (8.8) | — | — | Mooncake StoreAI | 6/10/2026 | 6/10/2026 | Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects… | |
| Aplazada | Media (6.9) | — | — | Mooncake StoreAI | 6/10/2026 | 6/10/2026 | Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client… | |
| Aplazada | Alta (8.8) | — | — | Mooncake StoreAI | 6/10/2026 | 6/10/2026 | Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe… | |
| Aplazada | Crítica (9.3) | — | — | MooncakeAI | 6/10/2026 | 6/10/2026 | Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or… | |
| Aplazada | Alta (7) | — | — | WibukeyAI | 6/10/2026 | 6/10/2026 | In the WibuKey driver for Windows below Version 6.72, insufficient validation of user input when calculating the size of a kernel buffer could cause small amounts of data to be written outside the intended kernel buffer. This can lead to a system crash. Under unfavorable circumstances, adjacent kernel memory may be… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() iptfs_skb_reset_frag_walk() advances to the fragment containing @offset with an unbounded loop: walk->fragi is advanced and walk->frags[walk->fragi] is dereferenced without ever checking… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix runt reassembly panic from short inner tot_len When the start of an inner packet is split across two outer packets such that fewer than 4 bytes land at the end of the first one, __input_process_payload() saves those bytes as a runt… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue")… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: esp: downgrade zerocopy managed frags before mutating skb frags On the out-of-place output path (esp->inplace == false) ESP rewrites the skb frag array: esp_output_head() appends a trailer frag and esp_output_tail() replaces the frags with a… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modify() fails in siw_accept(), the QP's… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the MR's PD rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument: Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is IB_MR_REREG_PD |… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: A remote peer can craft an RDMA-Write/Read RETH so… | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: hold net_device reference under RCU in bundle creation xfrm_bundle_create() and xfrm_create_dummy_bundle() read dst->dev into a local pointer without taking a device reference, then pass it to xfrm_fill_dst(). A concurrent RTM_DELLINK replaces… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds MAX_DVFS_OPPS entries in buf.opps[]; a… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate dvfs_get_idx() may return an out-of-range index if the SCP firmware is buggy or returns a stale value. Only negative indexes were rejected, so a large index walked past info->opps and could… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages") dropped the access permission test from rxe_check_pagefault() and left only HMM_PFN_VALID. A page faulted in… | |
| Recibida | Sin puntuar | 0.18% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds rxe_get_mcg() publishes a newly allocated multicast group in rxe->mcg_tree before programming the backing Ethernet multicast address with rxe_mcast_add(), which runs outside… | |
| Recibida | Sin puntuar | 0.17% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed ib_device_get_netdev() intentionally returns a referenced net_device even when it is unregistering, so matching and cleanup callers can still find the association. The reference keeps struct… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: IB/iser: reject a remote invalidation of an unregistered direction A write command whose data is sent entirely as immediate data is not registered. iser_reg_mem_fastreg() takes the DMA key path and leaves rdma_reg[ISER_DIR_OUT].desc at NULL, while… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: wait for deferred control PDU completions before releasing the connection isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work item then runs… | |
| Recibida | Sin puntuar | 0.16% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer. | |
| Recibida | Sin puntuar | 0.15% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: guard against null kobj name In the client, if `init_path()` errors, the callee tries to clean up with `rtrs_clt_close_conns()`. However, this can lead to calling the event tracing code with `clt_path->kobj->name` being `NULL` and thus… |