Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2520 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.25%—Linux KernelNetapp H300sNetapp H410cNetapp H410s+218/6/202317/6/2026
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.
ModificadaAlta (7.8)0.53%💥 PoCLinux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+416/6/202317/6/2026
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
ModificadaAlta (7.1)0.44%—Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux9/6/202317/6/2026
A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.
ModificadaAlta (7.8)0.44%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+35/6/202317/6/2026
A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
ModificadaAlta (7.8)1.4%💥 PoCLinux KernelNetapp HCI Baseboard Management Controller1/6/202317/6/2026
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
ModificadaAlta (7.1)0.52%—Linux KernelNetapp H300sNetapp H410cNetapp H410s+231/5/202317/6/2026
An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.
ModificadaAlta (7.5)1.9%—OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+730/5/202317/6/2026
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
ModificadaMedia (4.7)0.19%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+326/5/202317/6/2026
There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
ModificadaMedia (5.3)0.57%—Netapp Blue XP Connector26/5/202317/6/2026
NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obtaining the fix requires redeploying a fresh Connector.
ModificadaBaja (3.7)2.2%—Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+526/5/202317/6/2026
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which…
ModificadaMedia (5.9)1.8%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+626/5/202317/6/2026
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private…
ModificadaMedia (5.9)2.7%—Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+426/5/202317/6/2026
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this,…
ModificadaAlta (7.5)2.5%—Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+426/5/202317/6/2026
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting…
ModificadaAlta (7.5)48%—Apache TomcatDebian LinuxNetapp 7-mode Transition Tool22/5/202317/6/2026
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly…
ModificadaMedia (4.4)0.25%—Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+121/5/202317/6/2026
The Linux kernel 6.3 has a use-after-free in iopt_unmap_iova_range in drivers/iommu/iommufd/io_pagetable.c.
ModificadaAlta (7.8)0.49%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+315/5/202317/6/2026
An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.
ModificadaCrítica (9.8)0.96%—Netapp Snapcenter12/5/202317/6/2026
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user.
ModificadaAlta (7.8)13%💥 PoCLinux KernelRedhat Enterprise LinuxNetapp HCI Baseboard Management Controller8/5/202317/6/2026
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
AnalizadaAlta (8.1)0.53%—Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+13/5/202317/6/2026
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (7.8)0.43%—Linux KernelNetapp HCI Baseboard Management Controller1/5/202317/6/2026
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past…
ModificadaAlta (7.5)2.4%💥 PoCLinux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+425/4/202317/6/2026
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the…
ModificadaMedia (4.4)0.22%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+425/4/202317/6/2026
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
AnalizadaAlta (7.5)64%⚠ Explotación activaNetapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+125/4/202317/6/2026
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
ModificadaAlta (7.8)0.29%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+424/4/202317/6/2026
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
ModificadaAlta (7)0.36%—Linux KernelNetapp HCI Baseboard Management Controller24/4/202317/6/2026
A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.