Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
10.164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.12% | — | BusyboxAIDebian DpkgAI | 23/9/2026 | 25/9/2026 | BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. | |
| Aplazada | Alta (7) | 0.18% | — | Linuxfabrik Monitoring PluginsAIDebian Apt-getAI | 18/8/2026 | 9/9/2026 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that… | |
| Aplazada | Media (6.2) | 0.17% | — | DebianAI | 13/8/2026 | 26/8/2026 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | |
| Analizada | Media (6) | 0.81% | — | OpenvpnDebian Linux | 30/7/2026 | 5/8/2026 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry | |
| Analizada | Media (5.3) | 0.28% | — | PHPDebian Linux | 3/7/2026 | 8/7/2026 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for… | |
| Modificada | Media (5.3) | 0.41% | — | GNU SaslDebian Linux | 23/6/2026 | 31/7/2026 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server. | |
| Aplazada | Media (5.3) | 0.21% | — | GNU TARAIUbuntuAIDebianAICentosAI | 17/6/2026 | 22/6/2026 | The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extraction path traversal was… | |
| Aplazada | Media (6.5) | 0.27% | — | DebusineAIDebianAI | 10/6/2026 | 17/6/2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the files that make up the artifact. The parser used to read these files in Debusine accepted arbitrary fully user-controlled… | |
| Modificada | Alta (7.5) | 4.2% | — | Apache Http ServerDebian Linux | 8/6/2026 | 19/8/2026 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. | |
| Modificada | Crítica (9.2) | 2.7% | — | F5 Nginx Open SourceF5 Nginx PlusF5 DOSF5 Nginx Gateway Fabric+8 | 22/5/2026 | 25/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple… | |
| Modificada | Alta (7.1) | 0.51% | — | Linux KernelDebian Linux | 15/5/2026 | 24/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Alta (7.8) | 0.22% | — | Ocaml OpamDebian LinuxRedhat Enterprise Linux | 16/4/2026 | 15/7/2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. | |
| Analizada | Media (4.4) | 0.16% | — | LibpngDebian Linux | 9/4/2026 | 17/6/2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair… | |
| Modificada | Alta (7.8) | 0.38% | — | LibtiffRedhat Hardened ImagesDebian LinuxRedhat Enterprise Linux | 24/3/2026 | 15/7/2026 | A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a… | |
| Analizada | Alta (7.5) | 0.22% | — | Freedesktop Gst-plugins-goodGstreamerDebian LinuxRedhat Enterprise Linux | 23/3/2026 | 17/6/2026 | An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes… | |
| Analizada | Alta (7.8) | 1.0% | — | AwstatsDebian Linux | 20/3/2026 | 17/6/2026 | AWStats 8.0 is vulnerable to Command Injection via the open function | |
| Modificada | Media (6.9) | 1.3% | — | Canonical Ubuntu LinuxOpenbsd OpensshDebian LinuxRedhat Enterprise Linux | 12/3/2026 | 15/7/2026 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an… | |
| Analizada | Alta (7.5) | 0.42% | — | Debian Dpkg | 7/3/2026 | 17/6/2026 | It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU). | |
| Modificada | Alta (7.8) | 0.28% | — | Opensuse MungeDebian Linux | 10/2/2026 | 15/7/2026 | MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge… | |
| Analizada | Baja (1.7) | 0.46% | — | Eprosima Fast DDSDebian Linux | 3/2/2026 | 17/6/2026 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition,… | |
| Analizada | Alta (7.2) | 0.51% | — | Eprosima Fast DDSDebian Linux | 3/2/2026 | 17/6/2026 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a heap buffer overflow exists in the Fast-DDS DATA_FRAG receive path. An un authenticated sender can transmit a single malformed RTPS DATA_FRAG packet… | |
| Analizada | Baja (1.7) | 0.53% | — | Eprosima Fast DDSDebian Linux | 3/2/2026 | 17/6/2026 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is the DDS Security control-message container that carries not only the handshake but also on going security-control traffic after the handshake, such as crypto-token… | |
| Analizada | Baja (1.7) | 0.52% | — | Eprosima Fast DDSDebian Linux | 3/2/2026 | 17/6/2026 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overflow, resulting in… | |
| Modificada | Alta (7.5) | 0.44% | — | Eprosima Fast DDSDebian Linux | 3/2/2026 | 17/6/2026 | eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM)… |