Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

452 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.93%💥 PoCLinux KernelBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+1523/11/202017/6/2026
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
ModificadaMedia (6.7)0.42%—Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.42%—Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Out of bounds write in Intel BIOS platform sample code for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.42%—Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Use of potentially dangerous function in Intel BIOS platform sample code for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.34%—Intel BiosNetapp Cloud BackupNetapp Fas/aff BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.52%—Intel MicrocodeNetapp Clustered Data OntapNetapp HCI Compute Node BiosNetapp HCI Storage Node Bios+1312/11/202017/6/2026
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.44%—Intel MicrocodeNetapp Clustered Data OntapNetapp HCL Compute Node BiosNetapp HCI Storage Node Bios+312/11/202017/6/2026
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaCrítica (9.8)3.6%—Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+922/10/202017/6/2026
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
AnalizadaMedia (5.3)3.2%—Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+1521/10/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can…
AnalizadaBaja (3.1)2.7%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.7)2.2%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.1)2.5%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaMedia (4.2)2.2%—Oracle OpenjdkOracle JDKOracle JREDebian Linux+1521/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.7)2.3%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1321/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
AnalizadaBaja (3.7)3.8%—Oracle OpenjdkOracle JDKOracle JREDebian Linux+1521/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (7.5)2.4%—Linux KernelDebian LinuxNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+313/10/202017/6/2026
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this…
ModificadaAlta (7.2)6.4%—PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+427/9/202017/6/2026
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
ModificadaAlta (7.8)0.67%—Linux KernelNetapp Cloud BackupNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+210/9/202017/6/2026
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use…
ModificadaMedia (6.5)0.87%—Espressif Esp-idf31/8/202017/6/2026
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the…
ModificadaMedia (6.5)0.81%—Espressif Esp-idf31/8/202017/6/2026
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
ModificadaAlta (7.8)0.38%—Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp HCI Management Node+220/8/202017/6/2026
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
ModificadaAlta (7.8)0.46%—Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp Smi-s Provider+120/8/202017/6/2026
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
ModificadaAlta (7.8)1.0%💥 PoCLinux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+619/8/202017/6/2026
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
ModificadaBaja (3.7)5.3%—Linux KernelOpensuse LeapFedoraproject FedoraDebian Linux+1130/7/202017/6/2026
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
AnalizadaAlta (7.4)13%💥 PoCOpenbsd OpensshNetapp A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+524/7/202017/6/2026
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking…
Orbitaley — Vulnerabilidades