Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

583 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.26%—Octopus DeployOctopus Server7/10/202117/6/2026
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
ModificadaAlta (7)2.5%💥 PoCOpenbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+826/9/202114/7/2026
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of…
ModificadaMedia (5.3)5.3%💥 PoCOpenbsd OpensshNetapp Clustered Data OntapNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+115/9/202117/6/2026
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not…
ModificadaAlta (7.3)1.7%—VIMFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility15/9/202117/6/2026
vim is vulnerable to Use After Free
ModificadaAlta (7.8)1.7%—VIMFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility15/9/202117/6/2026
vim is vulnerable to Heap-based Buffer Overflow
ModificadaMedia (6.5)1.6%—Simplesystems LibtiffDebian LinuxNetapp Ontap Select Deploy Administration Utility9/9/202117/6/2026
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.
ModificadaAlta (7.8)0.73%—VIMFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility6/9/202117/6/2026
vim is vulnerable to Heap-based Buffer Overflow
ModificadaMedia (6.1)0.71%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication11/8/202117/6/2026
UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites.
ModificadaAlta (7.5)2.7%—Nettle Project NettleRedhat Enterprise LinuxDebian LinuxNetapp Ontap Select Deploy Administration Utility5/8/202117/6/2026
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
ModificadaMedia (5.5)0.66%—Kernel Util-linuxNetapp Ontap Select Deploy Administration Utility30/7/202117/6/2026
An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.
ModificadaCrítica (9.1)2.6%—GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+322/7/202117/6/2026
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have…
ModificadaAlta (7.5)0.99%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication22/7/202117/6/2026
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
ModificadaMedia (6.5)2.0%—Xmlsoft Libxml2Redhat Jboss Core ServicesOracle ZFS Storage Appliance KITNetapp Active IQ Unified Manager+159/7/202117/6/2026
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
ModificadaMedia (4.3)0.64%—IBM Urbancode Deploy8/7/202117/6/2026
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Force ID: 200965.
ModificadaAlta (8.8)0.66%—Jenkins Xebialabs XL Deploy10/6/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.
ModificadaMedia (6.5)0.99%—Jenkins Xebialabs XL Deploy10/6/202117/6/2026
An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.
ModificadaMedia (4.3)1.0%—Jenkins Xebialabs XL Deploy10/6/202117/6/2026
A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.
ModificadaMedia (4.3)0.95%—Jenkins Xebialabs XL Deploy10/6/202117/6/2026
A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
ModificadaAlta (7.5)2.4%—GNU BinutilsNetapp Ontap Select Deploy Administration Utility2/6/202117/6/2026
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
ModificadaCrítica (9.8)3.2%—LZ4 Project LZ4Netapp Active IQ Unified ManagerNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+32/6/202117/6/2026
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some…
ModificadaAlta (7.8)2.0%—Xmlsoft XmllintDebian LinuxFedoraproject FedoraRedhat Jboss Core Services+51/6/202117/6/2026
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.
ModificadaAlta (7.7)53%💥 ExploitF5 NginxOpenrestyFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+91/6/202117/6/2026
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
ModificadaMedia (6.5)1.2%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+927/5/202117/6/2026
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
ModificadaAlta (7.4)6.1%—ISC DhcpFedoraproject FedoraDebian LinuxSiemens Ruggedcom ROX Rx1400 Firmware+1226/5/202117/6/2026
In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those…
ModificadaMedia (6.5)1.0%—Redhat LibvirtNetapp Ontap Select Deploy Administration Utility24/5/202117/6/2026
A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the…