Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.73% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.92% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 1.8% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 11/3/2022 | 17/6/2026 | Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 11/3/2022 | 17/6/2026 | Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 11/3/2022 | 17/6/2026 | Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 11/3/2022 | 17/6/2026 | Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2. | |
| Modificada | Alta (7) | 1.4% | 💥 PoC | PythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 10/3/2022 | 17/6/2026 | In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A… | |
| Modificada | Media (6.5) | 4.7% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+16 | 10/3/2022 | 17/6/2026 | There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to… | |
| Modificada | Alta (7.5) | 12% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+13 | 4/3/2022 | 17/6/2026 | A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability. | |
| Analizada | Media (6.5) | 1.4% | — | Redhat LibvirtRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration UtilityDebian Linux | 2/3/2022 | 17/6/2026 | An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could… | |
| Modificada | Media (6.3) | 0.49% | — | Redhat LibvirtRedhat Openshift Container PlatformRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility | 2/3/2022 | 17/6/2026 | A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity. | |
| Modificada | Alta (7.5) | 5.1% | — | Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+31 | 26/2/2022 | 17/6/2026 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | |
| Modificada | Alta (8.8) | 4.1% | — | Cyrusimap Cyrus-saslDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+4 | 24/2/2022 | 17/6/2026 | In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. | |
| Modificada | Media (5.5) | 0.43% | — | Kernel Util-linuxNetapp Ontap Select Deploy Administration Utility | 21/2/2022 | 17/6/2026 | A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw… | |
| Modificada | Media (4.3) | 1.6% | — | SqliteNetapp Ontap Select Deploy Administration Utility | 14/2/2022 | 17/6/2026 | A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information.… | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility | 11/2/2022 | 17/6/2026 | Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffRedhat Enterprise LinuxFedoraproject FedoraDebian Linux+1 | 11/2/2022 | 17/6/2026 | Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with commit eecb0712. | |
| Modificada | Alta (7.5) | 8.3% | — | PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+6 | 9/2/2022 | 17/6/2026 | A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a… | |
| Modificada | Media (6.1) | 0.56% | — | Octopus DeployOctopus Server | 7/2/2022 | 17/6/2026 | In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffDebian LinuxNetapp Ontap Select Deploy Administration Utility | 10/1/2022 | 17/6/2026 | LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field. | |
| Modificada | Alta (7.8) | 1.3% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+1 | 15/12/2021 | 17/6/2026 | stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699. | |
| Modificada | Alta (7.5) | 50% | 💥 PoC | OpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+12 | 14/12/2021 | 17/6/2026 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as… | |
| Modificada | Alta (7.5) | 1.0% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 27/10/2021 | 17/6/2026 | Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query. | |
| Modificada | Media (6.5) | 2.1% | — | SambaDebian LinuxNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+1 | 12/10/2021 | 17/6/2026 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. |