Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.2)0.43%—Ansible Automation PlatformAIRsyslogAI23/9/202624/9/2026
A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE — into an rsyslog RainerScript config file…
Pendiente de análisisAlta (8.1)0.94%—RsyslogAI18/9/202624/9/2026
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A…
Pendiente de análisisAlta (8.2)0.85%—RsyslogAI18/9/202624/9/2026
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic Authorization value exceeds its fixed work buffer, then passes that pointer to…
Pendiente de análisisAlta (7.5)0.71%—RsyslogAI27/8/202625/9/2026
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful…
AplazadaAlta (8.6)0.48%—Logtape SyslogAI26/8/20269/9/2026
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F in structured data values, and formatStructuredData() inserts property…
ModificadaAlta (7.5)0.47%—RsyslogRedhat Enterprise Linux12/8/202624/9/2026
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been…
AplazadaAlta (7.1)0.27%—Syslog-ngAIBalabit Syslog-ng Premium EditionAIOneidentity Syslog-ng Store BOXAI20/7/202623/7/2026
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver…
AnalizadaAlta (7.5)0.37%—Oneidentity Syslog-ngDebian Linux7/5/202517/6/2026
syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided / invalidated. This issue could have an impact on TLS…
ModificadaMedia (4.8)0.39%—Wp2syslog Project Wp2syslog16/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.
ModificadaAlta (7.5)2.4%—Oneidentity Syslog-ngOneidentity Syslog-ng Store BOX23/1/202317/6/2026
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
ModificadaAlta (8.1)3.9%—RsyslogFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager6/5/202217/6/2026
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execution. But there may…
ModificadaMedia (4.3)0.96%—Solarwinds Kiwi Syslog Server29/10/202117/6/2026
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have…
ModificadaMedia (5.3)0.52%—Solarwinds Kiwi Syslog Server27/10/202117/6/2026
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the…
ModificadaMedia (5.3)1.3%—Solarwinds Kiwi Syslog Server27/10/202117/6/2026
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the…
ModificadaMedia (5.3)0.96%—Solarwinds Kiwi Syslog Server27/10/202117/6/2026
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the…
ModificadaMedia (6.7)0.27%—Solarwinds Kiwi Syslog Server25/10/202117/6/2026
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:…
ModificadaAlta (7.8)0.52%—Oneidentity Syslog-ng29/6/202017/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux…
ModificadaMedia (5.5)0.38%—RsyslogDebian LinuxOpensuse14/11/201916/6/2026
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than…
ModificadaMedia (5.5)0.47%—RsyslogOpensuseDebian Linux14/11/201916/6/2026
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more…
ModificadaMedia (5.5)0.48%—RsyslogOpensuseDebian Linux14/11/201916/6/2026
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of…
ModificadaCrítica (9.8)3.1%—RsyslogFedoraproject FedoraDebian LinuxOpensuse Leap7/10/201917/6/2026
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not…
ModificadaCrítica (9.8)4.4%—RsyslogDebian LinuxFedoraproject FedoraOpensuse Leap7/10/201917/6/2026
An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do not satisfy this constraint. If the string…
ModificadaCrítica (9.8)2.4%—Rsyslog30/9/201917/6/2026
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
ModificadaAlta (7.5)2.2%—RsyslogRedhat Virtualization ManagerRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+825/1/201917/6/2026
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
ModificadaCrítica (9.8)9.3%—Rsyslog LibrelpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+523/3/201817/6/2026
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially…