Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.25% | — | Teradata DatabaseAISuse Linux Enterprise ServerAI | 8/1/2025 | 17/6/2026 | Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts,… | |
| Modificada | Alta (7.8) | 0.30% | — | Opensuse LeapSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Desktop | 19/9/2023 | 17/6/2026 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1;… | |
| Modificada | Media (6.4) | 1.6% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 29/7/2020 | 17/6/2026 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of… | |
| Modificada | Media (6.4) | 0.98% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and… | |
| Modificada | Media (6.4) | 1.4% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects… | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.4% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.9% | — | Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 23/3/2020 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.5% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.4% | — | Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+2 | 23/3/2020 | 17/6/2026 | Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (5) | 1.3% | — | Nextcloud ServerOpensuse Backports SLENovell Suse Linux Enterprise Server | 4/2/2020 | 17/6/2026 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. | |
| Modificada | Media (4.9) | 1.5% | — | Nextcloud ServerOpensuse BackportsSuse Linux Enterprise Server | 4/2/2020 | 17/6/2026 | Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Media (5.5) | 0.43% | — | Yast2-rmt Project Yast2-rmtOpensuse LeapSuse Linux Enterprise Server | 27/1/2020 | 17/6/2026 | A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt… | |
| Modificada | Alta (8.8) | 39% | — | PhpmyadminSuse Linux Enterprise ServerDebian Linux | 9/1/2020 | 17/6/2026 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server. | |
| Modificada | Alta (7.5) | 3.2% | — | EglibcNovell Suse Linux Enterprise ServerDebian LinuxCanonical Ubuntu Linux+1 | 31/12/2019 | 16/6/2026 | The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeDebian LinuxFedoraproject FedoraNovell Suse Package HUB FOR Suse Linux Enterprise+5 | 10/12/2019 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.1) | 0.34% | — | Suse Linux Enterprise Server | 7/10/2019 | 17/6/2026 | The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by… | |
| Modificada | Alta (8.3) | 2.6% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+2 | 23/7/2019 | 17/6/2026 | As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | |
| Modificada | Media (5.3) | 2.1% | — | Mozilla FirefoxMozilla ThunderbirdDebian LinuxNovell Suse Package HUB FOR Suse Linux Enterprise+1 | 23/7/2019 | 17/6/2026 | A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | |
| Modificada | Alta (8.8) | 2.4% | — | FfmpegDebian LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseCanonical Ubuntu Linux | 19/4/2019 | 17/6/2026 | libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data. | |
| Modificada | Alta (8.8) | 2.9% | — | Dcraw Project DcrawSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 29/11/2018 | 17/6/2026 | A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file. | |
| Modificada | Alta (7.5) | 41% | — | Nodejs Node.jsSuse Enterprise StorageSuse Linux Enterprise ServerSuse Openstack Cloud | 28/11/2018 | 17/6/2026 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time. |