Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

853 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.6)7.1%💥 PoCPythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityNetapp Snapcenter+113/4/202217/6/2026
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or…
ModificadaAlta (7)0.33%—Linux KernelRedhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+118/4/202217/6/2026
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
ModificadaMedia (5.5)1.1%—LibtiffNetapp Active IQ Unified Manager28/3/202217/6/2026
Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.
ModificadaMedia (6.8)1.7%—Linux KernelNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Element Software+1225/3/202217/6/2026
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.
ModificadaAlta (7.5)52%💥 PoCNokogiriPythonZlibDebian Linux+2325/3/202214/7/2026
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
ModificadaAlta (8.8)2.2%—Linux KernelNetapp Active IQ Unified ManagerNetapp H500s FirmwareNetapp H700s Firmware+616/3/202217/6/2026
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
ModificadaMedia (5.5)0.35%—Linux KernelNetapp Active IQ Unified ManagerNetapp H500s FirmwareNetapp H700s Firmware+612/3/202217/6/2026
An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
ModificadaAlta (7.5)4.9%💥 PoCFasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+3211/3/202217/6/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModificadaAlta (7)1.4%💥 PoCPythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility10/3/202217/6/2026
In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A…
ModificadaAlta (7.1)1.5%💥 PoCLibtiffDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager10/3/202217/6/2026
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
ModificadaMedia (6.5)1.5%—LibtiffDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager10/3/202217/6/2026
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
ModificadaMedia (5.5)1.5%—Apache POINetapp Active IQ Unified Manager4/3/202217/6/2026
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to…
ModificadaAlta (7.5)5.1%—Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+3126/2/202217/6/2026
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
ModificadaAlta (8.8)4.1%—Cyrusimap Cyrus-saslDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+424/2/202217/6/2026
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
AnalizadaAlta (7.4)6.9%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+1718/2/202230/7/2026
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this…
ModificadaMedia (4.6)0.92%💥 PoCLinux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+516/2/202217/6/2026
An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.
ModificadaMedia (4.7)0.36%—Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Element Software+816/2/202217/6/2026
A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.
ModificadaAlta (7.5)8.3%—PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+69/2/202217/6/2026
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a…
ModificadaAlta (7.5)2.7%—Apache ArtemisNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation4/2/202217/6/2026
In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.
ModificadaMedia (5.5)2.7%—Google ProtobufDebian LinuxFedoraproject FedoraOracle Mysql+426/1/202217/6/2026
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
ModificadaMedia (6.5)12%—Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+2524/1/202225/8/2026
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version…
ModificadaMedia (5.3)3.2%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+1519/1/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with…
ModificadaMedia (5.3)3.5%—Oracle GraalvmOracle JDKOracle JREDebian Linux+1519/1/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated…
ModificadaMedia (5.3)3.5%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+1519/1/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated…
ModificadaMedia (5.3)3.8%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+1519/1/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows…