Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.13% | — | SudoAI | 23/9/2026 | 24/9/2026 | A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local… | |
| Pendiente de análisis | Alta (8.5) | 0.13% | — | SudoAI | 29/8/2026 | 10/9/2026 | Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging. | |
| Aplazada | Media (6.4) | 0.33% | — | Sudoku ShortcodeAI | 10/7/2026 | 10/7/2026 | The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background' parameter in the 'sudoku-sc' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (7.8) | 0.18% | — | Sudo Project SudoSiemens Sinec OS | 3/4/2026 | 1/9/2026 | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. | |
| Aplazada | Media (4.4) | 0.17% | — | Sudo-rsAI | 12/11/2025 | 17/6/2026 | sudo-rs is a memory safe implementation of sudo and su written in Rust. With `Defaults targetpw` (or `Defaults rootpw`) enabled, the password of the target account (or root account) instead of the invoking user is used for authentication. sudo-rs starting in version 0.2.5 and prior to version 0.2.10 incorrectly… | |
| Aplazada | Baja (3.8) | 0.14% | — | Sudo-rsAI | 12/11/2025 | 17/6/2026 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not press return for an extended period, a password timeout may occur. When this happens, the keystrokes that were entered are echoed back to the… | |
| Analizada | Alta (7.8) | 61% | ⚠ Explotación activa | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Modificada | Alta (8.8) | 4.4% | — | Sudo Project Sudo | 30/6/2025 | 14/7/2026 | Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. | |
| Analizada | Baja (3.3) | 0.26% | — | Trifectatech Sudo | 12/5/2025 | 17/6/2026 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers… | |
| Analizada | Baja (3.3) | 0.36% | — | Trifectatech Sudo | 12/5/2025 | 17/6/2026 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges can determine whether files exists in folders that they otherwise cannot access using `sudo --list <pathname>`. Users with local access to a machine can discover the… | |
| Analizada | Crítica (9.8) | 0.32% | — | Onesoftnet Sudobot | 3/9/2024 | 17/6/2026 | SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of v9 before v9.26.7 is affected. Other… | |
| Modificada | Alta (8.8) | 0.69% | — | Sudo Project Sudo | 23/12/2023 | 17/6/2026 | A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them. | |
| Modificada | Alta (7) | 0.54% | — | Sudo Project Sudo | 22/12/2023 | 17/6/2026 | Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit. | |
| Modificada | Alta (8.1) | 0.63% | — | Memorysafety Sudo | 21/9/2023 | 17/6/2026 | Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, but instead only requiring authentication every once in a while in every terminal or process group. Only once a configurable timeout has passed will the user have to re-authenticate themselves.… | |
| Modificada | Media (5.3) | 0.95% | — | Sudo Project SudoNetapp Active IQ Unified Manager | 16/3/2023 | 17/6/2026 | Sudo before 1.9.13 does not escape control characters in sudoreplay output. | |
| Modificada | Media (5.3) | 0.92% | — | Sudo Project SudoNetapp Active IQ Unified Manager | 16/3/2023 | 17/6/2026 | Sudo before 1.9.13 does not escape control characters in log messages. | |
| Modificada | Alta (7.2) | 1.7% | — | Sudo Project SudoFedoraproject Fedora | 28/2/2023 | 17/6/2026 | Sudo before 1.9.13p2 has a double free in the per-command chroot feature. | |
| Modificada | Alta (7.8) | 55% | — | Sudo Project SudoDebian LinuxFedoraproject FedoraApple Macos | 18/1/2023 | 17/6/2026 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are… | |
| Modificada | Alta (7.1) | 0.28% | — | Sudo Project Sudo | 2/11/2022 | 17/6/2026 | Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could… | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa | Sudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+20 | 26/1/2021 | 17/6/2026 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| Modificada | Alta (7.8) | 1.1% | — | Sudo Project SudoNetapp HCI Management NodeNetapp SolidfireFedoraproject Fedora | 12/1/2021 | 17/6/2026 | selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable. | |
| Modificada | Baja (2.5) | 1.0% | — | Sudo Project SudoNetapp Cloud BackupNetapp HCI Management NodeNetapp Solidfire+2 | 12/1/2021 | 17/6/2026 | The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path. | |
| Modificada | Alta (7.8) | 19% | — | Sudo Project SudoDebian Linux | 29/1/2020 | 17/6/2026 | In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an… | |
| Modificada | Alta (7.5) | 3.2% | — | Sudo | 19/12/2019 | 17/6/2026 | In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software maintainer believes that this CVE is… | |
| Modificada | Alta (7.5) | 3.3% | — | Sudo | 19/12/2019 | 17/6/2026 | In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in… |