Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

889 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.8%—Oracle OpenjdkNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage ManagerNetapp E-series Santricity WEB Services+220/10/202117/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction…
ModificadaMedia (5.3)16%—Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+1020/10/202117/6/2026
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network…
ModificadaMedia (5.3)8.5%—Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+1020/10/202117/6/2026
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network…
ModificadaMedia (5.9)7.4%—Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+920/10/202117/6/2026
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network…
ModificadaCrítica (9.1)1.8%—Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+14223/9/202117/6/2026
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory…
ModificadaAlta (7.4)50%💥 PoCOpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+2824/8/202117/6/2026
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a…
ModificadaCrítica (9.8)88%—OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+2724/8/202117/6/2026
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the…
ModificadaMedia (6.7)0.27%—Intel Atom C3000Intel Atom C3308Intel Atom C3336Intel Atom C3338+106016/8/202117/6/2026
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (8.8)9.1%—Cisco Small Business RV Series Router Firmware4/8/202117/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about…
ModificadaCrítica (9.8)9.7%—Cisco Small Business RV Series Router Firmware4/8/202117/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about…
ModificadaCrítica (9.8)2.0%—Cisco Small Business RV Series Router Firmware4/8/202117/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient user input…
ModificadaCrítica (9.1)2.6%—GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+322/7/202117/6/2026
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have…
ModificadaMedia (6.8)0.30%—Cisco IP Phone 8800 FirmwareCisco IP Phone 8800 Series With Multiplatform FirmwareCisco IP Phone 8811 FirmwareCisco IP Phone 8811 With Multiplatform Firmware+1122/7/202117/6/2026
The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone…
ModificadaMedia (5.3)99%💥 ExploitEclipse JettyNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB ServicesNetapp Element Plug-in FOR Vcenter Server+1415/7/202117/6/2026
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
ModificadaMedia (6.7)0.33%—Intel Atom C3000Intel Atom C3308Intel Atom C3336Intel Atom C3338+106014/7/202117/6/2026
Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaBaja (3.5)0.96%💥 PoCEclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+1222/6/202117/6/2026
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated.…
ModificadaAlta (7.5)1.4%—Netapp E-series Santricity OS Controller11/6/202117/6/2026
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.
ModificadaAlta (8.8)1.2%—Netapp E-series Santricity OS Controller11/6/202117/6/2026
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow privileged attackers to execute arbitrary code.
ModificadaMedia (5.3)1.4%—Netapp E-series Santricity OS Controller11/6/202117/6/2026
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to cause a partial Denial of Service (DoS) to the web server.
ModificadaMedia (6.5)1.1%—Netapp E-series Santricity OS Controller11/6/202117/6/2026
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging which may aid in crafting more complex attacks.
ModificadaMedia (6.7)0.30%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+49/6/202117/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.30%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+59/6/202117/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (4.4)0.30%—Intel BiosSiemens Simatic Ipc547g FirmwareNetapp Cloud BackupNetapp AFF Bios+59/6/202117/6/2026
Out of bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.35%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+159/6/202117/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.35%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+79/6/20217/10/2026
Out of bounds read in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.