Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.64% | — | Netapp Clustered Data Ontap | 12/10/2023 | 17/6/2026 | ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service. | |
| Modificada | Alta (8.8) | 0.59% | — | Netapp Snapcenter | 12/10/2023 | 17/6/2026 | SnapCenter versions 3.x and 4.x prior to 4.9 are susceptible to a vulnerability which may allow an authenticated unprivileged user to gain access as an admin user. | |
| Modificada | Media (4.3) | 0.36% | — | Netapp Snapcenter Plug-in | 12/10/2023 | 17/6/2026 | SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authenticated unprivileged users to modify email and snapshot name settings within the VMware vSphere user interface. | |
| Modificada | Media (5.5) | 0.16% | — | Netapp Snapgathers | 12/10/2023 | 17/6/2026 | SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials | |
| Modificada | Alta (7.5) | 3.8% | 💥 PoC | Golang GOGolang Http2Fedoraproject FedoraNetapp Astra Trident+1 | 11/10/2023 | 17/6/2026 | A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.5) | 1.4% | — | LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraRedhat Enterprise Linux | 5/10/2023 | 17/6/2026 | LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosFedoraproject Fedora+10 | 21/9/2023 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | |
| Modificada | Alta (7.5) | 2.2% | — | ISC BindFedoraproject FedoraDebian LinuxNetapp H300s Firmware+4 | 20/9/2023 | 17/6/2026 | A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1… | |
| Modificada | Media (6.5) | 1.7% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+23 | 18/9/2023 | 17/6/2026 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a… | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+12 | 14/9/2023 | 17/6/2026 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. | |
| Modificada | Media (5.9) | 1.9% | 💥 PoC | GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems EUS S390x+12 | 12/9/2023 | 17/6/2026 | A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or… | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraDebian LinuxMozilla Firefox+8 | 12/9/2023 | 17/6/2026 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | |
| Modificada | Alta (7.5) | 1.5% | — | Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+1 | 31/8/2023 | 17/6/2026 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest… | |
| Modificada | Alta (7.5) | 2.6% | — | PythonNetapp Active IQ Unified Manager | 23/8/2023 | 17/6/2026 | An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but… | |
| Modificada | Media (5.9) | 1.3% | — | PythonDebian LinuxNetapp Active IQ Unified ManagerNetapp Converged Systems Advisor Agent | 22/8/2023 | 17/6/2026 | An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. | |
| Modificada | Media (6.5) | 1.7% | — | PythonNetapp Active IQ Unified Manager | 22/8/2023 | 17/6/2026 | read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format. | |
| Modificada | Media (5.5) | 0.64% | — | GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. | |
| Modificada | Media (5.5) | 0.61% | — | GNU BinutilsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. | |
| Analizada | Crítica (9.8) | 1.3% | — | Netapp Active IQ Unified ManagerJson-c | 22/8/2023 | 17/6/2026 | An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit. | |
| Modificada | Media (6.5) | 1.8% | — | Invisible-island NcursesNetapp Active IQ Unified Manager | 22/8/2023 | 23/7/2026 | Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. | |
| Modificada | Media (6.5) | 2.2% | — | Invisible-island NcursesNetapp Active IQ Unified ManagerDebian Linux | 22/8/2023 | 23/7/2026 | Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. | |
| Modificada | Media (6.5) | 1.8% | — | Invisible-island NcursesNetapp Active IQ Unified Manager | 22/8/2023 | 23/7/2026 | Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. | |
| Modificada | Media (6.5) | 1.8% | — | Invisible-island NcursesNetapp Active IQ Unified Manager | 22/8/2023 | 23/7/2026 | Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command. |