Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
5177 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | — | — | Canonical Postgresql OperatorAI | 2/10/2026 | 2/10/2026 | The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which… | |
| Recibida | Media (5.3) | — | — | Canonical MaasAI | 2/10/2026 | 2/10/2026 | An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker… | |
| Pendiente de análisis | Media (5.7) | 0.11% | — | Canonical WSL PRO ServiceAI | 29/9/2026 | 30/9/2026 | In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding… | |
| Aplazada | Alta (7.7) | 0.21% | — | Canonical LXDAI | 28/9/2026 | 28/9/2026 | Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the… | |
| Aplazada | Crítica (9.9) | 0.41% | — | Canonical LXDAI | 28/9/2026 | 29/9/2026 | Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files… | |
| Aplazada | Media (5.8) | 0.19% | — | Canonical LXDAI | 28/9/2026 | 28/9/2026 | Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client… | |
| Aplazada | Media (6.3) | 0.22% | — | Canonical LXDAI | 28/9/2026 | 28/9/2026 | Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests. | |
| Aplazada | Media (4.2) | 0.34% | — | Canonical LXDAI | 28/9/2026 | 28/9/2026 | Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite arbitrary local files and execute code on the client system via a crafted… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Canonical LXDAI | 28/9/2026 | 29/9/2026 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs… | |
| Aplazada | Crítica (9.6) | 0.36% | — | Canonical LXDAI | 28/9/2026 | 28/9/2026 | Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can… | |
| Pendiente de análisis | Sin puntuar | 0.17% | — | LibicalAI | 24/9/2026 | 24/9/2026 | libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function pointer type. bsearch() invokes the callback through… | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | IcalendarAI | 22/9/2026 | 23/9/2026 | icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expand it without an application-level limit. Alarms.times and Alarms.active reach the… | |
| Aplazada | Alta (7.1) | 0.20% | — | MythicaldashAI | 17/9/2026 | 23/9/2026 | MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embeds the payment code in the success redirect, while GET /api/stripe/processed… | |
| Aplazada | Alta (8.1) | 0.35% | — | Oracle E-business SuiteAIOracle CRM Technical FoundationAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Trtek Technological Products Products StoreAI | 1/9/2026 | 1/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2. | |
| Aplazada | Media (6.8) | 0.23% | — | Leyan Medical Practice Management SystemAI | 28/8/2026 | 28/8/2026 | Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files. | |
| Aplazada | Alta (7.5) | 0.63% | — | IcalendarAI | 25/8/2026 | 9/9/2026 | icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child components, causing O(2^n)… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Trtek Technological Products Software Repository ManagementAI | 25/8/2026 | 26/8/2026 | Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository Management: before 2fb4acee. | |
| Aplazada | Alta (8.6) | 0.64% | — | Leyan Medical Practice Management SystemAI | 25/8/2026 | 26/8/2026 | Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page. | |
| Analizada | Crítica (9.9) | 0.72% | — | Canonical LXD | 24/8/2026 | 11/9/2026 | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a… | |
| Pendiente de análisis | Media (6.7) | 0.20% | — | Canonical ApportAI | 20/8/2026 | 28/8/2026 | Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files. | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to… | |
| Aplazada | Alta (7.8) | 0.24% | — | Compugroup Medical CGM Isis MEDAI | 17/8/2026 | 31/8/2026 | An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file. | |
| Analizada | Crítica (9.9) | 0.59% | — | Canonical LXD | 12/8/2026 | 11/9/2026 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by… |