Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2306 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.8)0.63%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+116/4/202417/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.…
AnalizadaMedia (4.9)0.97%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+116/4/202417/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
AnalizadaMedia (5.3)0.98%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+116/4/202417/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.…
AnalizadaMedia (4.9)1.1%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+116/4/202417/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
AplazadaMedia (5.4)0.43%💥 PoCChangeweb UnifiedtransformAI9/4/202417/6/2026
Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.
AplazadaCrítica (9.8)1.2%—UI Unifi Network ApplicationAI4/4/202417/6/2026
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device. Affected Products: UniFi Network…
AnalizadaMedia (6.1)0.50%—Cisco Unified Communications Manager IM AND Presence Service3/4/202417/6/2026
A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface. This vulnerability exists because the web-based…
AnalizadaAlta (8.6)36%—Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+1027/3/202417/6/2026
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.…
AnalizadaMedia (6.3)1.7%—Haxx CurlApple MacosNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+827/3/202417/6/2026
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
AplazadaCrítica (9.9)0.51%—Hitachi Virtual Storage PlatformAIHitachi Virtual Storage Platform Vp9500AIHitachi Virtual Storage Platform G1000AIHitachi Virtual Storage Platform G1500AI+3725/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi Virtual Storage Platform G1000, G1500, Hitachi Virtual Storage Platform F1500, Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, Hitachi Virtual Storage Platform…
AplazadaMedia (5.4)0.32%—Avsystem Unified Management PlatformAI18/3/202417/6/2026
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to redirect authenticated users to malicious websites.
AplazadaMedia (5.9)0.46%—Avsystem Unified Management PlatformAI18/3/202417/6/2026
Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipment) devices storing arbitrarily large amounts of data during registration. This can potentially lead to DDoS attacks on the application database and, ultimately, affect…
AplazadaMedia (6.5)0.46%—Avsystem Unified Management PlatformAI18/3/202417/6/2026
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.
ModificadaMedia (5.5)0.21%—Avsystem Unified Management Platform18/3/202417/6/2026
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.
ModificadaMedia (5.5)0.58%—Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+1018/3/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h variable after this call as it can change skb->head.
AnalizadaAlta (8.1)2.6%—Vmware Spring FrameworkNetapp Active IQ Unified Manager16/3/202417/6/2026
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is…
ModificadaAlta (7.5)2.0%💥 PoCLibexpat Project LibexpatFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+1010/3/202417/6/2026
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
ModificadaMedia (5.5)0.44%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+429/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
AnalizadaAlta (7.5)1.1%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+529/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
AnalizadaMedia (5.3)0.81%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+529/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
AnalizadaMedia (6.6)0.32%—Cisco Firepower Extensible Operating SystemCisco Nx-osCisco Unified Computing System29/2/202417/6/2026
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame.…
ModificadaAlta (7.5)1.4%—Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp Bluexp26/2/202417/6/2026
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new…
AnalizadaAlta (7.1)0.14%—Cisco Unified Intelligence Center21/2/202417/6/2026
A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control implementations on cluster…
AplazadaAlta (7.5)0.52%—UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI20/2/202417/6/2026
A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi…
ModificadaAlta (7.5)4.6%—Netapp Active IQ Unified ManagerNetapp Oncommand Workflow AutomationRedhat FuseRedhat Integration Camel FOR Spring Boot+519/2/20247/10/2026
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits…