Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)2.5%💥 PoCOpenbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+826/9/202114/7/2026
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of…
ModificadaCrítica (9.8)1.3%—Infinispan-server-restRedhat Data Grid21/9/202117/6/2026
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as…
ModificadaMedia (5.3)5.3%💥 PoCOpenbsd OpensshNetapp Clustered Data OntapNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+115/9/202117/6/2026
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not…
ModificadaAlta (7.3)1.7%—VIMFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility15/9/202117/6/2026
vim is vulnerable to Use After Free
ModificadaAlta (7.8)1.7%—VIMFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility15/9/202117/6/2026
vim is vulnerable to Heap-based Buffer Overflow
ModificadaMedia (6.5)1.6%—Simplesystems LibtiffDebian LinuxNetapp Ontap Select Deploy Administration Utility9/9/202117/6/2026
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.
ModificadaAlta (7.8)0.73%—VIMFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility6/9/202117/6/2026
vim is vulnerable to Heap-based Buffer Overflow
ModificadaAlta (7.5)2.7%—Nettle Project NettleRedhat Enterprise LinuxDebian LinuxNetapp Ontap Select Deploy Administration Utility5/8/202117/6/2026
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
ModificadaMedia (5.5)0.66%—Kernel Util-linuxNetapp Ontap Select Deploy Administration Utility30/7/202117/6/2026
An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.
ModificadaCrítica (9.1)2.6%—GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+322/7/202117/6/2026
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have…
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaAlta (7.5)1.7%—Oracle Hyperion Essbase Administration Services21/7/202117/6/2026
Vulnerability in the Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Console). Supported versions that are affected are 11.1.2.4 and 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration…
ModificadaAlta (8.6)1.7%—Oracle Hyperion Essbase Administration Services21/7/202117/6/2026
Vulnerability in the Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Console). Supported versions that are affected are 11.1.2.4 and 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration…
ModificadaMedia (6.1)1.5%—Antisamy Project AntisamyOracle Retail Back OfficeOracle Retail Central OfficeOracle Retail Returns Management+719/7/202117/6/2026
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.
ModificadaMedia (5.5)2.6%—Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+3214/7/202125/8/2026
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR…
ModificadaMedia (5.5)2.5%—Apache ANTOracle Agile Product Lifecycle ManagementOracle Banking Trade FinanceOracle Banking Treasury Management+2814/7/202125/8/2026
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
ModificadaAlta (7.5)13%—Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+3013/7/202117/6/2026
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
ModificadaAlta (7.5)11%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Apis+2313/7/202117/6/2026
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
ModificadaAlta (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+2013/7/202117/6/2026
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModificadaAlta (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+2213/7/202117/6/2026
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModificadaMedia (6.5)2.0%—Xmlsoft Libxml2Redhat Jboss Core ServicesOracle ZFS Storage Appliance KITNetapp Active IQ Unified Manager+159/7/202117/6/2026
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
ModificadaAlta (7.5)2.4%—GNU BinutilsNetapp Ontap Select Deploy Administration Utility2/6/202117/6/2026
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
ModificadaCrítica (9.8)3.2%—LZ4 Project LZ4Netapp Active IQ Unified ManagerNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+32/6/202117/6/2026
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some…
ModificadaAlta (7.1)0.45%—Infinispan-server-restRedhat Data GridNetapp Oncommand Insight2/6/202117/6/2026
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
ModificadaAlta (7.8)2.0%—Xmlsoft XmllintDebian LinuxFedoraproject FedoraRedhat Jboss Core Services+51/6/202117/6/2026
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.
Orbitaley — Vulnerabilidades