Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.5) | 0.22% | — | Linux KernelRedhat Enterprise LinuxNetapp A700s FirmwareNetapp Brocade Fabric Operating System Firmware+14 | 26/3/2021 | 17/6/2026 | A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process. | |
| Modificada | Media (5.3) | 2.6% | — | Gnome GlibBroadcom Brocade Fabric Operating System FirmwareDebian LinuxFedoraproject Fedora | 11/3/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is… | |
| Modificada | Media (6.8) | 1.4% | — | Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+1 | 11/3/2021 | 19/8/2026 | Azure Virtual Machine Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 3.0% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption. | |
| Modificada | Alta (7.5) | 4.1% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation. | |
| Modificada | Media (5.4) | 0.52% | — | Tibco BPM EnterpriseTibco BPM Enterprise Distribution FOR Silver Fabric | 26/1/2021 | 17/6/2026 | The Application Development Clients component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Cross Site Scripting (XSS) attack on the affected… | |
| Modificada | Media (5.9) | 3.6% | — | GNU GlibcFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp Service Processor+4 | 4/1/2021 | 17/6/2026 | The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. | |
| Modificada | Media (5.5) | 1.3% | — | GNU BinutilsRedhat Enterprise LinuxNetapp HCI Compute Node FirmwareNetapp Cloud Backup+4 | 4/1/2021 | 17/6/2026 | There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (6.1) | 1.1% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (4.3) | 0.88% | — | Broadcom Fabric Operating System | 11/12/2020 | 17/6/2026 | Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges if it is not associated with any groups. | |
| Modificada | Media (6.7) | 0.31% | — | Broadcom Fabric Operating System | 11/12/2020 | 17/6/2026 | Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated user to run arbitrary commands and perform escalation of privileges. | |
| Modificada | Alta (7.8) | 1.1% | 💥 PoC | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+8 | 9/12/2020 | 17/6/2026 | A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. | |
| Modificada | Media (4.4) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 9/12/2020 | 17/6/2026 | A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24. | |
| Modificada | Media (6.7) | 0.93% | 💥 PoC | Linux KernelBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+15 | 23/11/2020 | 17/6/2026 | Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field. | |
| Modificada | Media (6.5) | 0.89% | — | Cisco Edge FOG Fabric | 6/11/2020 | 17/6/2026 | A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device. The vulnerability is due to incorrect authorization enforcement on an affected system. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.8) | 0.58% | — | Redhat Fabric8-maven | 22/10/2020 | 17/6/2026 | A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat… | |
| Modificada | Crítica (9.8) | 1.2% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input. | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated attackers to perform various attacks. | |
| Modificada | Media (5.5) | 0.34% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging. | |
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability. | |
| Modificada | Media (6.5) | 1.0% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files. | |
| Modificada | Alta (8.8) | 1.0% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host. |