Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1306▼ 184 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)3.7%—Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated Storage+177/4/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
ModificadaAlta (7.8)6.0%💥 PoCLinux KernelFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+232/4/202017/6/2026
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was…
AnalizadaAlta (8.8)6.3%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2831/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
AnalizadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2731/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2131/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2726/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
ModificadaAlta (8.8)3.6%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2726/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
ModificadaAlta (8.8)8.0%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2718/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
ModificadaAlta (8.8)3.1%—Fasterxml Jackson-databindDebian LinuxNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+2718/3/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
ModificadaAlta (8.8)23%—Djangoproject DjangoDebian LinuxFedoraproject FedoraNetapp Steelstore Cloud Integrated Storage+15/3/202017/6/2026
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject…
ModificadaMedia (5.5)0.76%—GNU GlibcFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+74/3/202017/6/2026
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to…
ModificadaCrítica (9.8)4.1%—Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Steelstore Cloud Integrated StorageOracle Goldengate Stream Analytics2/3/202017/6/2026
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using…
ModificadaMedia (5.5)0.52%—Linux KernelFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+525/2/202017/6/2026
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause…
ModificadaAlta (7.1)0.76%—Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+825/2/202017/6/2026
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
ModificadaMedia (5.5)0.42%—Linux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+614/2/202017/6/2026
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
ModificadaMedia (6.7)0.45%—Intel Converged Security Management Engine FirmwareNetapp Steelstore Cloud Integrated Storage13/2/202017/6/2026
Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
ModificadaCrítica (9.8)27%💥 PoCFasterxml Jackson-databindDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+410/2/202017/6/2026
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
ModificadaAlta (7.5)7.8%—Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+2021/1/202017/6/2026
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
ModificadaAlta (7.5)3.1%—Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+2021/1/202017/6/2026
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
ModificadaBaja (2.4)0.43%—Systemd Project SystemdCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+321/1/202017/6/2026
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
ModificadaMedia (5.3)2.6%—Linux KernelDebian LinuxNetapp A700s FirmwareNetapp 8300 Firmware+1016/1/202017/6/2026
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the…
ModificadaBaja (3.7)4.2%—Oracle JDKOracle JREOracle OpenjdkDebian Linux+1915/1/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
ModificadaBaja (3.7)4.0%—Oracle JDKOracle JRERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1915/1/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of…
ModificadaAlta (8.1)4.9%—Oracle Commerce Experience ManagerOracle Commerce Guided SearchOracle GraalvmOracle JDK+2315/1/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols…
ModificadaMedia (6.8)4.3%—Oracle JDKOracle JREOracle OpenjdkDebian Linux+1915/1/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise…