Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+1 | 3/11/2023 | 17/6/2026 | A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then… | |
| Modificada | Alta (8.8) | 9.5% | 💥 PoC | Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+1 | 1/11/2023 | 17/6/2026 | A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+2 | 27/10/2023 | 17/6/2026 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or… | |
| Modificada | Media (5.9) | 0.47% | — | Oracle SUN ZFS Storage Appliance KIT | 17/10/2023 | 17/6/2026 | Vulnerability in the Sun ZFS Storage Appliance product of Oracle Systems (component: Core). The supported version that is affected is 8.8.60. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance. Successful attacks of this vulnerability… | |
| Modificada | Media (5.3) | 1.4% | — | Oracle Graalvm FOR JDKOracle JDKOracle JRENetapp Cloud Insights Acquisition Unit+1 | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf, 11.0.20, 17.0.8, 21; Oracle GraalVM for JDK: 17.0.8, 21; Oracle GraalVM Enterprise Edition: 20.3.11,… | |
| Modificada | Media (5.3) | 0.89% | — | Oracle JDKOracle JRENetapp Cloud Insights Acquisition UnitNetapp Cloud Insights Storage Workload Security Agent | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Baja (3.7) | 0.89% | — | Oracle Graalvm FOR JDKOracle JDKOracle JRENetapp Cloud Insights Acquisition Unit+1 | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u381-perf, 17.0.8, 21; Oracle GraalVM for JDK: 17.0.8, 21; Oracle GraalVM Enterprise Edition: 21.3.7 and 22.3.3.… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5.4) | 0.29% | — | HPE MSA 1060 Storage FirmwareHPE MSA 2060 Storage FirmwareHPE MSA 2062 Storage Firmware | 9/10/2023 | 17/6/2026 | HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP requests. | |
| Modificada | Alta (7.8) | 0.24% | — | IBM Storage ProtectIBM Storage Protect Client | 6/10/2023 | 17/6/2026 | IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246. | |
| Modificada | Crítica (9.8) | 0.94% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability affecting user authentication. Dell… | |
| Modificada | Alta (8.8) | 0.84% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or remote authenticated attacker could potentially exploit this vulnerability, leading to the ability to gain root-level access. | |
| Modificada | Media (6.5) | 0.59% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software v1.4 (and earlier) contains an Improper Input Validation vulnerability in RADIUS configuration. An authenticated remote attacker could potentially exploit this vulnerability, leading to gaining unauthorized access to data. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands. | |
| Modificada | Media (5.4) | 0.38% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI. A remote authenticated attacker could potentially exploit these issues, leading to various injection type… | |
| Modificada | Media (6.5) | 0.61% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface. A remote authenticated attacker could potentially exploit this vulnerability, leading to modify or write arbitrary files to arbitrary locations in the license container. | |
| Modificada | Alta (7.8) | 0.49% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local attacker could potentially exploit this vulnerability, leading to possible injection of parameters to curl or docker. | |
| Modificada | Alta (8.8) | 0.94% | — | Dell Smartfabric Storage Software | 5/10/2023 | 17/6/2026 | Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 0.56% | — | Purestorage Purity//fa | 3/10/2023 | 17/6/2026 | A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation. | |
| Modificada | Media (4.9) | 0.48% | — | Purestorage Purity//fa | 3/10/2023 | 17/6/2026 | A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection. | |
| Modificada | Baja (2.7) | 0.52% | — | Purestorage Purity//fa | 3/10/2023 | 17/6/2026 | A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the availability of data on the system including snapshots protected by SafeMode. | |
| Modificada | Baja (2.7) | 0.59% | — | Purestorage Purity | 2/10/2023 | 17/6/2026 | A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly. | |
| Modificada | Media (4.3) | 0.60% | — | Purestorage Purity | 2/10/2023 | 17/6/2026 | A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can impact the availability of the system’s data access and replication protocols. | |
| Modificada | Baja (2.7) | 0.55% | — | Purestorage Purity | 2/10/2023 | 17/6/2026 | A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock. | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosFedoraproject Fedora+10 | 21/9/2023 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. |