Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)74%—SambaDebian LinuxCanonical Ubuntu LinuxSynology Diskstation Manager+1921/2/202217/6/2026
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially…
ModificadaAlta (8.1)1.6%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2118/2/202217/6/2026
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
ModificadaMedia (5.9)1.8%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2018/2/202217/6/2026
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
ModificadaAlta (7.5)0.62%—IBM Resilient Security Orchestration Automation AND Response23/8/202117/6/2026
IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
ModificadaAlta (7.5)0.69%—IBM Resilient Security Orchestration Automation AND Response23/8/202117/6/2026
IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
ModificadaMedia (4.7)0.67%—IBM Resilient Security Orchestration Automation AND Response19/7/202117/6/2026
IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should not have access to due to improper input validation. IBM X-Force ID: 203085.
ModificadaMedia (4.4)0.11%—IBM Resilient Security Orchestration Automation AND Response16/6/202117/6/2026
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.
ModificadaAlta (7.5)0.71%—IBM Resilient Security Orchestration Automation AND Response16/6/202117/6/2026
IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.
ModificadaAlta (7.2)1.1%—IBM Resilient19/4/202117/6/2026
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.
ModificadaAlta (8.8)2.9%—IBM Resilient Security Orchestration Automation AND Response11/12/202017/6/2026
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
ModificadaMedia (4.3)0.45%—IBM Resilient Security Orchestration Automation AND Response29/10/202017/6/2026
IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address. IBM X-Force ID: 190567.
ModificadaAlta (7.2)1.1%—IBM Resilient Security Orchestration Automation AND Response16/10/202017/6/2026
IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.
ModificadaMedia (4.3)0.74%—IBM Resilient Security Orchestration Automation AND Response28/8/202017/6/2026
IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 167236.
ModificadaMedia (4.3)1.0%—IBM Resilient Security Orchestration Automation AND Response28/8/202017/6/2026
IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input validation. IBM X-Force ID: 165589.
ModificadaAlta (7.5)3.3%—Clusterlabs PacemakerOpensuse LeapOpensuse Project LeapSuse Linux Enterprise High Availability+324/3/201717/6/2026
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
ModificadaMedia (6.1)0.71%—IBM Resilient16/2/201717/6/2026
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference#: 213457065.
ModificadaAlta (7.5)3.0%—Redhat Enterprise Linux High AvailabilityRedhat Enterprise Linux Resilient StorageClusterlabs Pacemaker12/8/201517/6/2026
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
ModificadaMedia (6.8)2.4%—Fedora Pacemaker Configuration SystemRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUSRedhat Enterprise Linux Resilient Storage+114/5/201517/6/2026
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types.…