Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Virtio WIN ViosockAI | 18/9/2026 | 30/9/2026 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds… | |
| Analizada | Alta (7.8) | 0.10% | — | IBM AIXIBM Vios | 28/8/2026 | 2/9/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability. | |
| Analizada | Alta (7.8) | 0.11% | — | IBM ViosIBM AIX | 20/8/2026 | 26/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation. | |
| Analizada | Alta (8.8) | 0.14% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root. | |
| Analizada | Alta (7.5) | 0.25% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service. | |
| Analizada | Alta (7.5) | 1.0% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart. | |
| Analizada | Alta (8.8) | 0.12% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel. | |
| Analizada | Crítica (9.8) | 0.47% | — | IBM ViosIBM AIX | 20/8/2026 | 27/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | |
| Analizada | Alta (7.8) | 0.12% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write. | |
| Analizada | Alta (7.8) | 0.12% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer. | |
| Analizada | Crítica (9.9) | 0.79% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Crítica (9.8) | 0.59% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. | |
| Analizada | Alta (7.5) | 0.37% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. | |
| Analizada | Alta (8.8) | 0.41% | — | IBM ViosIBM AIX | 20/8/2026 | 4/9/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Media (5.5) | 0.10% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records. | |
| Analizada | Crítica (9.1) | 0.29% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. | |
| Analizada | Crítica (9.1) | 0.38% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow. | |
| Analizada | Crítica (9.8) | 0.59% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow. | |
| Analizada | Media (6.5) | 0.27% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Crítica (9.1) | 0.33% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read. | |
| Analizada | Alta (8.8) | 0.13% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. | |
| Analizada | Media (6.5) | 0.13% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write. | |
| Analizada | Alta (7.8) | 0.17% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM ViosIBM AIX | 20/8/2026 | 25/8/2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size. |