Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
853 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 3.8% | 💥 PoC | Libexpat Project LibexpatNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Baseboard Management Controller+4 | 6/1/2022 | 17/6/2026 | In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. | |
| Modificada | Alta (8.8) | 4.2% | 💥 PoC | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server+4 | 1/1/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.5) | 3.7% | — | Gmplib GMPDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+4 | 15/11/2021 | 17/6/2026 | GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms. | |
| Modificada | Media (4.3) | 1.4% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Metrocluster Tiebreaker+4 | 28/10/2021 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. | |
| Modificada | Media (6.3) | 50% | — | Oracle Mysql ClusterNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 20/10/2021 | 17/6/2026 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication… | |
| Modificada | Baja (1.8) | 0.68% | — | Oracle Mysql ClusterNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 20/10/2021 | 17/6/2026 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster… | |
| Modificada | Baja (3.7) | 4.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Baja (3.1) | 3.9% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Media (5.3) | 6.8% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 6.7% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Analizada | Media (6.8) | 2.9% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+12 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network… | |
| Modificada | Media (5.3) | 7.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 5.6% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 6.9% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 16% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 8.5% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.9) | 7.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+9 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (7) | 2.5% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+8 | 26/9/2021 | 14/7/2026 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Crítica (9.8) | 22% | — | Nodejs Node.jsNetapp Active IQ Unified ManagerNetapp Nextgen APINetapp Oncommand Insight+6 | 16/8/2021 | 17/6/2026 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in… | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Management Node+15 | 5/8/2021 | 17/6/2026 | libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or… | |
| Modificada | Alta (7.5) | 10% | — | MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 22/7/2021 | 17/6/2026 | ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation. | |
| Modificada | Crítica (9.1) | 2.6% | — | GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+3 | 22/7/2021 | 17/6/2026 | The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have… | |
| Modificada | Media (5.9) | 8.1% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+3 | 21/7/2021 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… |