Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.7) | 0.28% | — | Canonical Ubuntu Subiquity | 9/4/2026 | 30/9/2026 | In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs. | |
| Analizada | Alta (8.4) | 0.28% | — | Canonical Subiquity | 3/6/2024 | 17/6/2026 | Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions | |
| Modificada | Media (5.5) | 0.21% | — | Canonical Subiquity | 7/10/2023 | 17/6/2026 | Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege. | |
| Modificada | Baja (2.3) | 0.60% | — | Canonical Subiquity | 13/5/2020 | 17/6/2026 | It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered. |