Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Modificada | Alta (7.8) | 0.30% | — | Opensuse LeapSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Desktop | 19/9/2023 | 17/6/2026 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1;… | |
| Modificada | Alta (7.8) | 0.58% | — | Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+15 | 27/4/2022 | 17/6/2026 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… | |
| Modificada | Alta (7.1) | 0.39% | — | Lrzsz Project LrzszSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 2/6/2021 | 17/6/2026 | lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around. | |
| Modificada | Alta (7.8) | 0.29% | — | Suse Linux Enterprise Desktop | 4/5/2020 | 17/6/2026 | — | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.4% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.9% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.5% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.4% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.8) | 7.0% | — | ImagemagickSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 17/2/2020 | 17/6/2026 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than… | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Media (6.8) | 0.88% | — | Gnome NetworkmanagerOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 27/1/2020 | 16/6/2026 | NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used. | |
| Modificada | Media (6.5) | 3.6% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+4 | 23/1/2020 | 17/6/2026 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | |
| Modificada | Media (5.3) | 4.3% | — | LibgdPHPCanonical Ubuntu LinuxDebian Linux+9 | 19/6/2019 | 17/6/2026 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead… | |
| Modificada | Alta (7.5) | 5.6% | — | LibtiffOpensuse LeapSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 21/3/2019 | 17/6/2026 | LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue | |
| Modificada | Alta (8.8) | 2.9% | — | Dcraw Project DcrawSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 29/11/2018 | 17/6/2026 | A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file. | |
| Modificada | Alta (7.8) | 1.6% | — | Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. | |
| Modificada | Media (6.5) | 1.9% | — | Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service. | |
| Modificada | Alta (8.8) | 2.8% | — | Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,… | |
| Modificada | Alta (8.8) | 2.3% | — | Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,… |