Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 1.1% | — | UAC Unix Like Artifacts CollectorAI | 21/8/2026 | 24/9/2026 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by… | |
| Aplazada | Alta (8.5) | 1.0% | — | UAC Unix Like Artifacts CollectorAI | 21/8/2026 | 24/9/2026 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or filenames. Attackers can exploit this… | |
| Analizada | Alta (7.8) | 0.18% | — | Opengroup Unix | 13/3/2026 | 17/6/2026 | In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments. NOTE: This… | |
| Aplazada | Alta (8.4) | 0.11% | — | IBM Sterling Connect Direct FOR UnixAI | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to… | |
| Aplazada | Alta (8.5) | 0.59% | — | Broadcom Automic Automation Agent UnixAI | 20/5/2025 | 17/6/2026 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges. | |
| Aplazada | Alta (7.8) | 0.21% | — | Sunix Parallel DriverAI | 7/1/2025 | 17/6/2026 | A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These… | |
| Aplazada | Alta (7.8) | 0.21% | — | Sunix Serial DriverAI | 7/1/2025 | 17/6/2026 | A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed… | |
| Aplazada | Alta (8.8) | 0.40% | — | Sunix Multi I O CardAI | 7/1/2025 | 17/6/2026 | An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests. | |
| Modificada | Alta (7.8) | 0.28% | — | Unixodbc | 18/3/2024 | 17/6/2026 | An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken. | |
| Modificada | Crítica (9.8) | 1.1% | — | Unix4lyfe Darkhttpd | 22/1/2024 | 17/6/2026 | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel. | |
| Modificada | Media (5.5) | 0.24% | — | Unix4lyfe Darkhttpd | 22/1/2024 | 17/6/2026 | darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments. | |
| Modificada | Alta (7.5) | 0.91% | — | Protocol Go-unixfsnode | 9/2/2023 | 17/6/2026 | github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot to 1.5.2 trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger… | |
| Modificada | Alta (7.5) | 0.68% | — | Protocol Go-unixfs | 9/2/2023 | 17/6/2026 | go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic. This is caused by bogus `fanout` parameter in the HAMT… | |
| Modificada | Alta (7.5) | 1.3% | — | Unix4lyfe Darkhttpd | 1/4/2022 | 17/6/2026 | A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability. | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa | Sudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+20 | 26/1/2021 | 17/6/2026 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| Modificada | Alta (7.8) | 0.45% | — | UnixodbcDebian LinuxOpensuseRedhat Enterprise Linux | 14/11/2019 | 16/6/2026 | The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string. | |
| Modificada | Crítica (9.8) | 3.0% | — | Unixodbc | 26/2/2018 | 17/6/2026 | The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact. | |
| Modificada | Crítica (9.8) | 2.5% | — | Unixodbc | 22/2/2018 | 17/6/2026 | In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c. | |
| Modificada | Crítica (9.8) | 42% | — | Quest Privilege Manager FOR Unix | 29/4/2017 | 17/6/2026 | Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon. | |
| Modificada | Crítica (9.8) | 3.0% | — | LHA FOR Unix Project LHA FOR Unix | 23/1/2017 | 17/6/2026 | Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow. | |
| Modificada | Alta (7.2) | 0.84% | — | IBM Monitoring Agent FOR Unix LogsIBM Monitoring Server (ms) AND Shared Libraries (ax) | 29/8/2014 | 16/6/2026 | Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow… | |
| Modificada | Alta (7.2) | 0.39% | — | Nvidia Unix Graphic Driver | 19/11/2012 | 16/6/2026 | NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by modifying the VGA window using /dev/nvidia0. | |
| Modificada | Media (6.9) | 0.40% | — | Attachmate Reflection FOR HPAttachmate Reflection FOR IBMAttachmate Reflection FOR Regis Graphics ServerAttachmate Reflection FOR Unix AND Openvms+1 | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.1) | 0.51% | — | Unixodbc | 31/8/2012 | 16/6/2026 | Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to… | |
| Modificada | Baja (2.1) | 0.44% | — | Unixodbc | 31/8/2012 | 16/6/2026 | Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has… |