Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
518 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.4% | — | SqliteFedoraproject FedoraDebian LinuxOracle Communications Messaging Server+8 | 6/6/2020 | 17/6/2026 | SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. | |
| Modificada | Alta (7.4) | 3.3% | — | NTPNetapp Cloud BackupNetapp Clustered Data OntapNetapp Data Ontap+21 | 4/6/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query… | |
| Modificada | Crítica (9.8) | 1.4% | — | FreebsdNetapp Clustered Data Ontap | 29/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in accessing out-of-bounds memory leading to a kernel panic or other unpredictable results. | |
| Modificada | Crítica (9.8) | 1.4% | — | FreebsdNetapp Clustered Data Ontap | 29/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in memory access after it has been freed leading to a kernel panic or other unpredictable results. | |
| Modificada | Alta (7.5) | 2.1% | — | NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+13 | 17/4/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp. | |
| Modificada | Crítica (9.8) | 7.6% | — | SqliteNetapp Ontap Select Deploy Administration UtilityOracle Communications Network Charging AND ControlOracle Enterprise Manager OPS Center+8 | 9/4/2020 | 17/6/2026 | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement. | |
| Modificada | Alta (7.5) | 4.3% | — | SqliteNetapp Ontap Select Deploy Administration UtilityDebian LinuxCanonical Ubuntu Linux+14 | 9/4/2020 | 17/6/2026 | SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled. | |
| Modificada | Alta (7.5) | 7.8% | — | Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+20 | 21/1/2020 | 17/6/2026 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. | |
| Modificada | Alta (7.5) | 3.1% | — | Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+20 | 21/1/2020 | 17/6/2026 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. | |
| Modificada | Alta (7.5) | 5.6% | — | Xmlsoft Libxml2Debian LinuxOracle Real User Experience InsightFedoraproject Fedora+8 | 24/12/2019 | 17/6/2026 | xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. | |
| Modificada | Crítica (9.8) | 5.4% | — | SqliteSiemens Sinec Infrastructure Network ServicesTenable.scOracle Mysql Workbench+2 | 9/12/2019 | 17/6/2026 | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns. | |
| Modificada | Alta (7.5) | 8.0% | — | SqliteOracle Mysql WorkbenchSiemens Sinec Infrastructure Network ServicesApache Guacamole+2 | 9/12/2019 | 17/6/2026 | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. | |
| Modificada | Media (5.5) | 0.57% | — | SqliteNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityOracle Mysql Workbench+2 | 9/12/2019 | 17/6/2026 | alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements. | |
| Modificada | Crítica (9.8) | 4.3% | — | SqliteNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityOracle Mysql Workbench+1 | 5/12/2019 | 17/6/2026 | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. | |
| Modificada | Crítica (9.8) | 2.3% | — | Netapp Ontap Select Deploy Administration Utility | 21/11/2019 | 17/6/2026 | ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account. | |
| Modificada | Alta (7.2) | 1.3% | — | Netapp Ontap Select Deploy Administration Utility | 21/11/2019 | 17/6/2026 | All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges. | |
| Modificada | Alta (7.5) | 1.3% | — | Netapp Clustered Data Ontap | 25/10/2019 | 17/6/2026 | Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service (DoS). | |
| Modificada | Alta (8.1) | 3.8% | 💥 PoC | Libssh2Fedoraproject FedoraOpensuse LeapDebian Linux+6 | 21/10/2019 | 17/6/2026 | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service… | |
| Modificada | Media (5.9) | 0.82% | — | Netapp Clustered Data Ontap | 9/10/2019 | 17/6/2026 | Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks. | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Apache Http ServerOpensuse LeapDebian LinuxRedhat Software Collection+6 | 26/9/2019 | 17/6/2026 | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but… | |
| Modificada | Crítica (9.8) | 0.84% | — | Netapp Ontap Select Deploy Administration Utility | 24/9/2019 | 17/6/2026 | ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. | |
| Modificada | Crítica (9.8) | 2.0% | — | Netapp Ontap Select Deploy Administration Utility | 24/9/2019 | 17/6/2026 | ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions. | |
| Modificada | Media (6.5) | 4.3% | — | SqliteNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Oncommand Insight+16 | 9/9/2019 | 17/6/2026 | In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." | |
| Modificada | Alta (7.5) | 0.91% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe. A multi-threaded program can exploit races in… | |
| Modificada | Alta (7.5) | 4.4% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check in the function to arrange data in a chain of mbufs could cause data returned not to be contiguous. Extra checks in the… |