Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.17% | — | Opensuse TumbleweedAISuricataAI | 14/7/2026 | 15/7/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1. | |
| Analizada | Media (6.9) | 0.18% | — | OpensmtpdOpensuse Tumbleweed | 20/11/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1. | |
| Aplazada | Alta (8.5) | 0.17% | — | Opensuse TumbleweedAITraefikAI | 2/9/2025 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29. | |
| Modificada | Alta (7.8) | 0.21% | — | Opensuse Tumbleweed | 7/7/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed. | |
| Modificada | Alta (7.8) | 0.32% | — | Opensuse Tumbleweed | 20/7/2022 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1. | |
| Modificada | Alta (7.8) | 0.36% | — | Opensuse Backports SLEOpensuse TumbleweedOpensuse Leap | 7/8/2020 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE… | |
| Modificada | Alta (7.8) | 0.50% | — | Opensuse LeapOpensuse Tumbleweed Kopano-spamd | 29/6/2020 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE… | |
| Modificada | Alta (9.3) | 35% | — | Tumbleweed Securetransport Server APP | 11/4/2008 | 16/6/2026 | Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in Tumbleweed SecureTransport Server before 4.6.1 Hotfix 20 allows remote attackers to execute arbitrary code via a long remoteFile parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Tumbleweed Email Firewall | 31/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remote attackers to inject arbitrary web script or HTML via the (1) lineId and (2) sort parameters. | |
| Modificada | Alta (7.5) | 3.6% | — | Tumbleweed Mailgate Email Firewall | 27/7/2006 | 16/6/2026 | Multiple stack-based buffer overflows in Tumbleweed Email Firewall (EMF) allow remote attackers to execute arbitrary code via an email attachment with an LHA archive that contains a (1) file or (2) directory with a long LHA extended header, (3) an LHA archive in which the "temporary pathname" field for decompressed… | |
| Modificada | Media (5) | 1.1% | — | Tumbleweed Mailgate Email Firewall | 1/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under "extremely heavy loads" and (2) cause an "increased number of missed spam" during "spam outbreaks." | |
| Modificada | Alta (7.5) | 1.4% | — | Tumbleweed Messaging Management System | 20/10/2000 | 16/6/2026 | The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password. |