Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.43% | — | Ansible Automation PlatformAIRsyslogAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE — into an rsyslog RainerScript config file… | |
| Pendiente de análisis | Alta (8.1) | 0.94% | — | RsyslogAI | 18/9/2026 | 24/9/2026 | Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A… | |
| Pendiente de análisis | Alta (8.2) | 0.85% | — | RsyslogAI | 18/9/2026 | 24/9/2026 | Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic Authorization value exceeds its fixed work buffer, then passes that pointer to… | |
| Pendiente de análisis | Alta (7.5) | 0.71% | — | RsyslogAI | 27/8/2026 | 25/9/2026 | A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful… | |
| Aplazada | Alta (8.6) | 0.48% | — | Logtape SyslogAI | 26/8/2026 | 9/9/2026 | LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F in structured data values, and formatStructuredData() inserts property… | |
| Modificada | Alta (7.5) | 0.47% | — | RsyslogRedhat Enterprise Linux | 12/8/2026 | 24/9/2026 | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been… | |
| Aplazada | Alta (7.1) | 0.27% | — | Syslog-ngAIBalabit Syslog-ng Premium EditionAIOneidentity Syslog-ng Store BOXAI | 20/7/2026 | 23/7/2026 | Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver… | |
| Analizada | Alta (7.5) | 0.37% | — | Oneidentity Syslog-ngDebian Linux | 7/5/2025 | 17/6/2026 | syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided / invalidated. This issue could have an impact on TLS… | |
| Modificada | Media (4.8) | 0.39% | — | Wp2syslog Project Wp2syslog | 16/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions. | |
| Modificada | Alta (7.5) | 2.4% | — | Oneidentity Syslog-ngOneidentity Syslog-ng Store BOX | 23/1/2023 | 17/6/2026 | An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected. | |
| Modificada | Alta (8.1) | 3.9% | — | RsyslogFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager | 6/5/2022 | 17/6/2026 | Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execution. But there may… | |
| Modificada | Media (4.3) | 0.96% | — | Solarwinds Kiwi Syslog Server | 29/10/2021 | 17/6/2026 | A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have… | |
| Modificada | Media (5.3) | 0.52% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the… | |
| Modificada | Media (5.3) | 1.3% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the… | |
| Modificada | Media (5.3) | 0.96% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the… | |
| Modificada | Media (6.7) | 0.27% | — | Solarwinds Kiwi Syslog Server | 25/10/2021 | 17/6/2026 | As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:… | |
| Modificada | Alta (7.8) | 0.52% | — | Oneidentity Syslog-ng | 29/6/2020 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux… | |
| Modificada | Media (5.5) | 0.38% | — | RsyslogDebian LinuxOpensuse | 14/11/2019 | 16/6/2026 | A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than… | |
| Modificada | Media (5.5) | 0.47% | — | RsyslogOpensuseDebian Linux | 14/11/2019 | 16/6/2026 | A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more… | |
| Modificada | Media (5.5) | 0.48% | — | RsyslogOpensuseDebian Linux | 14/11/2019 | 16/6/2026 | A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of… | |
| Modificada | Crítica (9.8) | 3.1% | — | RsyslogFedoraproject FedoraDebian LinuxOpensuse Leap | 7/10/2019 | 17/6/2026 | An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not… | |
| Modificada | Crítica (9.8) | 4.4% | — | RsyslogDebian LinuxFedoraproject FedoraOpensuse Leap | 7/10/2019 | 17/6/2026 | An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do not satisfy this constraint. If the string… | |
| Modificada | Crítica (9.8) | 2.4% | — | Rsyslog | 30/9/2019 | 17/6/2026 | contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled. | |
| Modificada | Alta (7.5) | 2.2% | — | RsyslogRedhat Virtualization ManagerRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+8 | 25/1/2019 | 17/6/2026 | A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable. | |
| Modificada | Crítica (9.8) | 9.3% | — | Rsyslog LibrelpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 23/3/2018 | 17/6/2026 | rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially… |