Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.7%—SqliteNetapp Cloud BackupCanonical Ubuntu LinuxSiemens Sinec Infrastructure Network Services+721/2/202017/6/2026
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.
ModificadaMedia (5.5)0.42%—Linux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+614/2/202017/6/2026
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
ModificadaAlta (7.1)0.66%—Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ Unified Manager+56/2/202017/6/2026
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
ModificadaAlta (7.5)3.1%—Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+2021/1/202017/6/2026
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
ModificadaBaja (2.4)0.43%—Systemd Project SystemdCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+321/1/202017/6/2026
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
ModificadaMedia (5.3)2.6%—Linux KernelDebian LinuxNetapp A700s FirmwareNetapp 8300 Firmware+1016/1/202017/6/2026
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the…
ModificadaMedia (5.9)3.3%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1015/1/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result…
ModificadaMedia (5.3)15%💥 PoCF5 NginxApple XcodeCanonical Ubuntu LinuxOpensuse Leap+19/1/202017/6/2026
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
ModificadaAlta (8.8)1.4%—Ahsay Cloud Backup Suite6/1/202017/6/2026
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible to upload a file into any directory of…
ModificadaMedia (5.5)0.39%—Linux KernelOpensuse LeapNetapp Active IQ Unified ManagerNetapp Cloud Backup+1030/12/201917/6/2026
mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID-003b686ace82. This will cause a memory leak and denial of service.
ModificadaMedia (5.5)0.48%—Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud BackupNetapp Data Availability Services+928/12/201917/6/2026
In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.
ModificadaMedia (4.6)0.63%—Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ Unified Manager+925/12/201917/6/2026
In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.
ModificadaMedia (4.7)0.65%—Linux KernelDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+1225/12/201917/6/2026
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
ModificadaAlta (7.5)6.8%—SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+724/12/201917/6/2026
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
ModificadaMedia (5.3)7.9%—SqliteSiemens Sinec Infrastructure Network ServicesApache BookkeeperOracle Mysql Workbench+124/12/201917/6/2026
SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.
ModificadaAlta (7.5)6.8%—SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+724/12/201917/6/2026
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
ModificadaMedia (4.6)0.49%—Linux KernelDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+924/12/201917/6/2026
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
ModificadaMedia (6.5)10%—Linux KernelDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+1223/12/201917/6/2026
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios,…
ModificadaAlta (7.5)7.0%—SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+723/12/201917/6/2026
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
ModificadaMedia (5.5)0.95%—Linux KernelOracle Sd-wan EdgeCanonical Ubuntu LinuxDebian Linux+1022/12/201917/6/2026
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice…
ModificadaAlta (7.5)6.9%—SqliteNetapp Cloud BackupDebian LinuxSuse Package HUB+718/12/201917/6/2026
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
ModificadaCrítica (9.8)5.4%—SqliteSiemens Sinec Infrastructure Network ServicesTenable.scOracle Mysql Workbench+29/12/201917/6/2026
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
ModificadaAlta (7.5)8.0%—SqliteOracle Mysql WorkbenchSiemens Sinec Infrastructure Network ServicesApache Guacamole+29/12/201917/6/2026
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
ModificadaMedia (5.5)0.57%—SqliteNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityOracle Mysql Workbench+29/12/201917/6/2026
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
ModificadaAlta (7.8)2.1%—Linux KernelDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+148/12/201917/6/2026
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right…
Orbitaley — Vulnerabilidades