Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 53% | 💥 Exploit | F5 NginxOpenrestyFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+9 | 1/6/2021 | 17/6/2026 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | |
| Modificada | Media (6.5) | 1.2% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+9 | 27/5/2021 | 17/6/2026 | An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command. | |
| Modificada | Alta (7.8) | 0.40% | — | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRM - Elastic Charging EngineOracle Communications Cloud Native Core Binding Support Function+28 | 27/5/2021 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or… | |
| Modificada | Alta (7.4) | 6.1% | — | ISC DhcpFedoraproject FedoraDebian LinuxSiemens Ruggedcom ROX Rx1400 Firmware+12 | 26/5/2021 | 17/6/2026 | In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those… | |
| Modificada | Media (6.5) | 1.0% | — | Redhat LibvirtNetapp Ontap Select Deploy Administration Utility | 24/5/2021 | 17/6/2026 | A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the… | |
| Modificada | Alta (7.5) | 2.0% | — | Webmproject LibwebpRedhat Enterprise LinuxDebian LinuxNetapp Ontap Select Deploy Administration Utility | 21/5/2021 | 17/6/2026 | A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. | |
| Modificada | Crítica (9.1) | 2.3% | — | Webmproject LibwebpRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration UtilityDebian Linux+2 | 21/5/2021 | 17/6/2026 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. | |
| Modificada | Crítica (9.1) | 2.2% | — | Webmproject LibwebpDebian LinuxRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility+2 | 21/5/2021 | 17/6/2026 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability. | |
| Modificada | Crítica (9.8) | 2.3% | — | Webmproject LibwebpRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration UtilityDebian Linux+2 | 21/5/2021 | 17/6/2026 | A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Crítica (9.8) | 2.7% | — | Webmproject LibwebpRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration UtilityDebian Linux+2 | 21/5/2021 | 17/6/2026 | A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Media (5.7) | 1.9% | — | PythonFedoraproject FedoraDebian LinuxRedhat Software Collections+6 | 20/5/2021 | 17/6/2026 | There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk… | |
| Modificada | Alta (8.6) | 17% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+24 | 19/5/2021 | 17/6/2026 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application… | |
| Modificada | Alta (8.8) | 22% | — | Xmlsoft Libxml2Debian LinuxRedhat Jboss Core ServicesRedhat Enterprise Linux+14 | 18/5/2021 | 17/6/2026 | There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability. | |
| Modificada | Media (5.9) | 3.5% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxDebian Linux+15 | 14/5/2021 | 17/6/2026 | A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this… | |
| Modificada | Media (6.1) | 1.1% | — | GNU WgetBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+2 | 29/4/2021 | 17/6/2026 | GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007. | |
| Modificada | Alta (8) | 0.68% | — | Tibco Administrator | 20/4/2021 | 17/6/2026 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator… | |
| Modificada | Alta (8.8) | 0.84% | — | Tibco Administrator | 20/4/2021 | 17/6/2026 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator… | |
| Modificada | Crítica (9.6) | 1.1% | — | Tibco AdministratorTibco Runtime Agent | 20/4/2021 | 17/6/2026 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator… | |
| Modificada | Media (4.8) | 9.9% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 13/4/2021 | 7/10/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Modificada | Alta (8.1) | 1.7% | — | Nettle Project NettleFedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+2 | 5/4/2021 | 17/6/2026 | A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to… | |
| Modificada | Media (5.5) | 1.3% | — | GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility | 26/3/2021 | 17/6/2026 | A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (6.3) | 0.30% | — | GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+2 | 26/3/2021 | 17/6/2026 | There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities… | |
| Modificada | Alta (7.4) | 18% | 💥 PoC | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Alta (7.8) | 1.9% | — | LibtiffDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+1 | 9/3/2021 | 17/6/2026 | A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |