Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

63 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.96%—Microsoft Power BI Report Server11/8/202619/8/2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
AnalizadaMedia (5.4)0.52%—Microsoft Power BI Report Server14/7/202619/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
ModificadaAlta (7.1)0.54%—Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+616/3/202617/6/2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.96%—Microsoft Power BI Report Server10/2/202619/8/2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
AplazadaCrítica (9.8)0.77%—Lens VisualAIMicrosoft Power BIAI5/11/202417/6/2026
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component
AnalizadaMedia (4.7)0.73%—Microsoft Power BI Report Server8/10/202419/8/2026
Power BI Report Server Spoofing Vulnerability
AnalizadaAlta (8.8)1.8%—Microsoft Power BI Report Server8/10/202419/8/2026
Power BI Report Server Spoofing Vulnerability
ModificadaMedia (5.4)0.32%—Atlaspolicy Power BI Embedded20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atlas Public Policy Power BI Embedded for WordPress allows Stored XSS.This issue affects Power BI Embedded for WordPress: from n/a through 1.1.7.
AnalizadaAlta (7.8)28%⚠ Explotación activaNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+1431/1/20247/8/2026
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when…
ModificadaAlta (7.8)0.36%—TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+818/1/202417/6/2026
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
ModificadaMedia (5.5)0.32%—TigervncX.org X ServerX.org XwaylandFedoraproject Fedora+818/1/202417/6/2026
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX…
ModificadaMedia (6.5)0.57%—FreeipaFedoraproject FedoraRedhat Codeready Linux BuilderRedhat Enterprise Linux+1710/1/202417/6/2026
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration…
ModificadaAlta (8.8)4.3%—PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+1710/12/202317/6/2026
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data.…
ModificadaAlta (7.8)0.27%—Redhat Insights-clientRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Desktop+151/11/202317/6/2026
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could…
ModificadaAlta (7.8)0.62%—X.org X ServerX.org XwaylandRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+825/10/202323/6/2026
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation…
AnalizadaAlta (7.8)64%⚠ Explotación activaNetapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+353/10/202317/6/2026
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated…
ModificadaAlta (7.8)0.24%—Redhat Subscription-managerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1623/8/202317/6/2026
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a…
ModificadaAlta (7.8)0.90%—X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1427/3/202317/6/2026
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote…
AnalizadaAlta (8.8)1.6%⚠ Explotación activaWebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+196/3/202317/6/2026
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
ModificadaAlta (8.2)0.78%—Microsoft Power BI Report Server14/2/202319/8/2026
Power BI Report Server Spoofing Vulnerability
ModificadaAlta (8.8)0.95%—Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+91/2/202317/6/2026
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
AnalizadaAlta (7.8)0.38%—Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+3425/3/20225/8/2026
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
ModificadaAlta (8.8)0.66%—Linux KernelFedoraproject FedoraRedhat Software CollectionsRedhat Openstack+224/3/202217/6/2026
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable…
ModificadaAlta (8.8)74%—SambaDebian LinuxCanonical Ubuntu LinuxSynology Diskstation Manager+1921/2/202217/6/2026
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially…
ModificadaAlta (7.5)2.0%—Port389 389-ds-baseRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR Power BIG Endian+418/2/202217/6/2026
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.