Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 12% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+13 | 4/3/2022 | 17/6/2026 | A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability. | |
| Analizada | Media (6.5) | 1.4% | — | Redhat LibvirtRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration UtilityDebian Linux | 2/3/2022 | 17/6/2026 | An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could… | |
| Modificada | Media (6.3) | 0.49% | — | Redhat LibvirtRedhat Openshift Container PlatformRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility | 2/3/2022 | 17/6/2026 | A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity. | |
| Modificada | Alta (7.5) | 5.1% | — | Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+31 | 26/2/2022 | 17/6/2026 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | |
| Modificada | Alta (8.8) | 4.1% | — | Cyrusimap Cyrus-saslDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+4 | 24/2/2022 | 17/6/2026 | In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. | |
| Modificada | Media (5.5) | 0.43% | — | Kernel Util-linuxNetapp Ontap Select Deploy Administration Utility | 21/2/2022 | 17/6/2026 | A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw… | |
| Modificada | Alta (7.8) | 0.45% | — | Malwarebytes Binisoft Windows Firewall Control | 14/2/2022 | 17/6/2026 | In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges. | |
| Modificada | Media (4.3) | 1.6% | — | SqliteNetapp Ontap Select Deploy Administration Utility | 14/2/2022 | 17/6/2026 | A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information.… | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility | 11/2/2022 | 17/6/2026 | Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffRedhat Enterprise LinuxFedoraproject FedoraDebian Linux+1 | 11/2/2022 | 17/6/2026 | Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with commit eecb0712. | |
| Modificada | Alta (7.5) | 8.3% | — | PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+6 | 9/2/2022 | 17/6/2026 | A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a… | |
| Modificada | Crítica (9.9) | 1.2% | — | Oracle Essbase Administration Services | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported version that is affected is Prior to 11.1.2.4.047. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase Administration… | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffDebian LinuxNetapp Ontap Select Deploy Administration Utility | 10/1/2022 | 17/6/2026 | LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field. | |
| Modificada | Alta (7.8) | 1.3% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+1 | 15/12/2021 | 17/6/2026 | stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699. | |
| Modificada | Alta (7.5) | 50% | 💥 PoC | OpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+12 | 14/12/2021 | 17/6/2026 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as… | |
| Modificada | Media (6.7) | 0.25% | — | Administrative Tools FOR Intel Network Adapters | 17/11/2021 | 17/6/2026 | Improper input validation in the Intel(R) Administrative Tools for Intel(R) Network Adapters driver for Windows before version 1.4.0.15, may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.26% | — | Administrative Tools FOR Intel Network Adapters | 17/11/2021 | 17/6/2026 | Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.4.0.21 may allow an unauthenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 1.2% | — | Oracle Essbase Administration Services | 20/10/2021 | 17/6/2026 | Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase… | |
| Modificada | Alta (7.5) | 1.6% | — | Oracle Essbase Administration Services | 20/10/2021 | 17/6/2026 | Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase… | |
| Modificada | Alta (7.7) | 1.2% | — | Oracle Essbase Administration Services | 20/10/2021 | 17/6/2026 | Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase… | |
| Modificada | Crítica (10) | 1.9% | — | Oracle Essbase Administration Services | 20/10/2021 | 17/6/2026 | Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase… | |
| Modificada | Alta (8.5) | 1.0% | — | Oracle Essbase Administration Services | 20/10/2021 | 17/6/2026 | Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase… | |
| Modificada | Media (6.5) | 2.1% | — | SambaDebian LinuxNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+1 | 12/10/2021 | 17/6/2026 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. | |
| Modificada | Media (6.1) | 9.9% | 💥 Exploit | Hkurl I-panel Administration System | 4/10/2021 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button. | |
| Modificada | Media (4.9) | 0.76% | — | Microfocus Netiq Directory AND Resource Administrator | 28/9/2021 | 17/6/2026 | Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure. |