Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.16% | — | Fedora DNFAISuse ZypperAIRedhat YUMAIOpensuse LibsolvAI | 28/8/2026 | 28/8/2026 | A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the… | |
| Pendiente de análisis | Alta (7.5) | 0.48% | — | Opensuse PCPAI | 30/7/2026 | 1/10/2026 | A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads. | |
| Pendiente de análisis | Alta (7.5) | 0.82% | — | Opensuse LibsolvAI | 16/7/2026 | 31/8/2026 | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted… | |
| Aplazada | Alta (7.1) | 0.17% | — | Opensuse TumbleweedAISuricataAI | 14/7/2026 | 15/7/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1. | |
| Analizada | Alta (8.8) | 0.53% | — | Opensuse Libzypp | 2/7/2026 | 7/7/2026 | A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root. | |
| Pendiente de análisis | Crítica (10) | 0.66% | — | Opensuse OBSAIOpensuse TAR SCMAI | 2/7/2026 | 2/7/2026 | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services | |
| Analizada | Alta (8.8) | 0.60% | — | Opensuse Libzypp | 29/6/2026 | 30/6/2026 | A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation. | |
| Modificada | Alta (7.8) | 0.26% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 26/5/2026 | 2/10/2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds… | |
| Modificada | Media (6.5) | 0.57% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 21/5/2026 | 1/9/2026 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to… | |
| Modificada | Media (6.5) | 0.58% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 20/5/2026 | 1/9/2026 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Aplazada | Alta (7) | 0.15% | — | Opensuse SdbootutilAI | 25/2/2026 | 17/6/2026 | This issue affects sdbootutil: from ? before 5880246d3a02642dc68f5c8cb474bf63cdb56bca. | |
| Modificada | Alta (7.8) | 0.28% | — | Opensuse MungeDebian Linux | 10/2/2026 | 15/7/2026 | MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge… | |
| Analizada | Media (6.9) | 0.18% | — | OpensmtpdOpensuse Tumbleweed | 20/11/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1. | |
| Aplazada | Alta (8.5) | 0.17% | — | Opensuse TumbleweedAITraefikAI | 2/9/2025 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29. | |
| Aplazada | Media (4.8) | 0.13% | — | Opensuse Mailman3AIGNU LogrotateAI | 23/7/2025 | 17/6/2026 | A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP to arbitrary processes. This issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1. | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Opensuse Cyrus-imapdAI | 26/5/2025 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1. | |
| Analizada | Media (5.3) | 0.33% | — | Opensuse Mirrorcache | 13/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters. This issue affects MirrorCache before 1.083. | |
| Aplazada | Media (5.5) | 0.21% | — | Opensuse OSCAI | 16/10/2024 | 17/6/2026 | Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim | |
| Aplazada | Alta (8.8) | 1.0% | — | RedisAICockpitAIOpensuse PCPAI | 28/3/2024 | 17/6/2026 | A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The… | |
| Modificada | Alta (7.8) | 0.30% | — | Opensuse LeapSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Desktop | 19/9/2023 | 17/6/2026 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1;… | |
| Modificada | Alta (7.8) | 0.31% | — | Opensuse Welcome | 19/9/2023 | 17/6/2026 | A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a. | |
| Modificada | Alta (7.8) | 0.21% | — | Opensuse Tumbleweed | 7/7/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed. | |
| Modificada | Media (6.5) | 0.57% | — | Opensuse Libeconf | 1/6/2023 | 17/6/2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuration files This issue affects libeconf: before 0.5.2. |