Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.25% | — | Linux KernelNetapp H300sNetapp H410cNetapp H410s+2 | 18/6/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c. | |
| Modificada | Alta (7.8) | 0.53% | 💥 PoC | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 16/6/2023 | 17/6/2026 | An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux | 9/6/2023 | 17/6/2026 | A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | |
| Modificada | Alta (7.8) | 0.44% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+3 | 5/6/2023 | 17/6/2026 | A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). | |
| Modificada | Alta (7.8) | 1.4% | 💥 PoC | Linux KernelNetapp HCI Baseboard Management Controller | 1/6/2023 | 17/6/2026 | A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation. | |
| Modificada | Alta (7.1) | 0.52% | — | Linux KernelNetapp H300sNetapp H410cNetapp H410s+2 | 31/5/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c. | |
| Modificada | Alta (7.5) | 1.9% | — | OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+7 | 30/5/2023 | 17/6/2026 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. | |
| Modificada | Media (4.7) | 0.19% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+3 | 26/5/2023 | 17/6/2026 | There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. | |
| Modificada | Media (5.3) | 0.57% | — | Netapp Blue XP Connector | 26/5/2023 | 17/6/2026 | NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obtaining the fix requires redeploying a fresh Connector. | |
| Modificada | Baja (3.7) | 2.2% | — | Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+5 | 26/5/2023 | 17/6/2026 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which… | |
| Modificada | Media (5.9) | 1.8% | — | Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+6 | 26/5/2023 | 17/6/2026 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private… | |
| Modificada | Media (5.9) | 2.7% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this,… | |
| Modificada | Alta (7.5) | 2.5% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting… | |
| Modificada | Alta (7.5) | 48% | — | Apache TomcatDebian LinuxNetapp 7-mode Transition Tool | 22/5/2023 | 17/6/2026 | The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly… | |
| Modificada | Media (4.4) | 0.25% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+1 | 21/5/2023 | 17/6/2026 | The Linux kernel 6.3 has a use-after-free in iopt_unmap_iova_range in drivers/iommu/iommufd/io_pagetable.c. | |
| Modificada | Alta (7.8) | 0.49% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+3 | 15/5/2023 | 17/6/2026 | An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Crítica (9.8) | 0.96% | — | Netapp Snapcenter | 12/5/2023 | 17/6/2026 | SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user. | |
| Modificada | Alta (7.8) | 13% | 💥 PoC | Linux KernelRedhat Enterprise LinuxNetapp HCI Baseboard Management Controller | 8/5/2023 | 17/6/2026 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled. | |
| Analizada | Alta (8.1) | 0.53% | — | Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+1 | 3/5/2023 | 17/6/2026 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelNetapp HCI Baseboard Management Controller | 1/5/2023 | 17/6/2026 | A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past… | |
| Modificada | Alta (7.5) | 2.4% | 💥 PoC | Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+4 | 25/4/2023 | 17/6/2026 | The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the… | |
| Modificada | Media (4.4) | 0.22% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+4 | 25/4/2023 | 17/6/2026 | A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. | |
| Analizada | Alta (7.5) | 64% | ⚠ Explotación activa | Netapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+1 | 25/4/2023 | 17/6/2026 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor. | |
| Modificada | Alta (7.8) | 0.29% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 24/4/2023 | 17/6/2026 | The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. | |
| Modificada | Alta (7) | 0.36% | — | Linux KernelNetapp HCI Baseboard Management Controller | 24/4/2023 | 17/6/2026 | A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel. |