Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
20.839 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.3) | — | — | Watchguard Kernel Memory Access DriverAI | 1/10/2026 | 1/10/2026 | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process… | |
| Pendiente de análisis | Sin puntuar | 0.19% | — | Linux KernelAI | 29/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be… | |
| Pendiente de análisis | Sin puntuar | 0.18% | — | Linux KernelAI | 26/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()") extended the lifetime of tasks on the dying_tasks list. The iterators have… | |
| Pendiente de análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: Disconnect the new tree connection if ksmbd_iov_pin_rsp() fails. | |
| Pendiente de análisis | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the bio data and can later overwrite the error with a successful REQ_FUA flush. That lets data writes run after a failed preflush and… | |
| Pendiente de análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to release this vmalloc-backed buffer can… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on teardown ucsi_register() creates per-instance debugfs entries, but ucsi_unregister() keeps them around until ucsi_destroy(). Drivers like ucsi_glink that unregister/register the same UCSI instance across… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to function The first argument to iwl_mei_write_cyclic_buf() should be the cldev but the q_head pointer is passed instead. Fix it. | |
| Pendiente de análisis | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit During recovery, it is not safe to retire the hung submit before we recover the GPU. Retiring the submit triggers BO free and that can result in GPU pagefaults since the GPU may be actively accessing those… | |
| Pendiente de análisis | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths issue_beacon(), issue_probersp() and issue_asocrsp() obtain a management xmit_frame together with its xmit_buf from the driver's fixed-size management-TX pools via… | |
| Pendiente de análisis | Crítica (9.8) | 0.42% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs… | |
| Pendiente de análisis | Sin puntuar | 0.15% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUNT is not marked as a unique field, while it should be. Fix this oversight. | |
| Pendiente de análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Commit 95ad8ee45cdb ("ext4: correct the reserved credits for extent conversion") was correct to note that we need to reserve enough credits for all extents possibly underlying a large folio. However it… | |
| Pendiente de análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() The acpi_get_first_physical_node() usage in acpi_platform_fill_resource() and acpi_create_platform_device() is generally unsafe because in theory the device returned by it may be freed at any time [1].… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on device setup failure hsr_dev_finalize() can fail after a lower-device RX handler has already been registered (slave A is added before the failable slave B and interlink adds). RX handlers run in softirq regardless of… | |
| Pendiente de análisis | Sin puntuar | 0.17% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP string is shorter or longer than the internal IP, coff will still point to the offset relative to… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: validate CLC firmware records The CLC region is supplied by firmware, but the loader trusts the region count and each record length. A malformed image can make the region table pointer precede the firmware buffer, make the record… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: ppp_async: drop the errored frame instead of resetting its headroom ppp_receive_nonmp_frame() prepends a two-byte direction tag before running the pass/active BPF filters: Nothing on the receive path guarantees those two bytes of headroom. The… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation The poll_msec sysfs store file uses simple_strtoul() which accepts an unsigned long, but the target field (poll_msec) is unsigned int. On 64-bit systems, a value > UINT_MAX is… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use the DMA API for resource backing on Xen On a Xen PV domain page addresses bear no relation to the real machine addresses the host would have to use to reach it. virtio_ring.c handles this correctly, vring_use_map_api() returns true for… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Address potential out-of-bounds read in resp_worker() Although 'commit 2feec5ae5df7 ("accel/qaic: Handle DBC deactivation if the owner went away")' fixes the scenario it was intended for by walking the message and only decoding… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup order in queue_rq On -EIO, the RDMA queue_rq path reports a host path error and then still cleans up the command and unmaps the SQE DMA. The path error helper completes the request, so that is double cleanup and DMA unmap… | |
| Pendiente de análisis | Sin puntuar | 0.14% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix racy access to FDP placement id array nvme_query_fdp_info() is called per-path and therefore prone to races. It populates head->nr_plids/head->plids for fdp registration. But nothing protects that pair from concurrent access - two paths… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix queue leak when connect backlog is exceeded When pending disconnecting queues exceed the backlog limit, the connect path only drops the device reference and leaks the newly allocated queue and its IB resources. | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Linux KernelAI | 25/9/2026 | 30/9/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic Take the following unprivileged program as an example: Loading it triggers a verifier warning from reg_bounds_sanity_check(): What happens: var_off and the 32-bit range must always be… |