Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1623 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.98% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 18/10/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.39 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Alta (7.5) | 3.4% | — | Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation | 2/10/2022 | 7/10/2026 | In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. | |
| Modificada | Alta (7.5) | 3.4% | — | Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation | 2/10/2022 | 7/10/2026 | In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Alienware UpdateDell Command UpdateDell Update | 2/9/2022 | 17/6/2026 | Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges. | |
| Modificada | Media (4.9) | 0.89% | — | Redhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Single Sign-on+5 | 1/9/2022 | 17/6/2026 | A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. | |
| Modificada | Alta (8.1) | 1.9% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571. | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591. | |
| Modificada | Media (5.5) | 0.21% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345. | |
| Modificada | Media (5.5) | 0.18% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554. | |
| Modificada | Media (6.5) | 0.49% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465. | |
| Modificada | Media (6.5) | 0.41% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825. | |
| Modificada | Media (6.5) | 0.41% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609. | |
| Modificada | Alta (7.8) | 0.22% | — | Dell Command | Integration Suite FOR System Center | 31/8/2022 | 17/6/2026 | Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary write as system. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Openshift Application RuntimesRedhat Single Sign-onRedhat UndertowNetapp Active IQ Unified Manager+3 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet… | |
| Modificada | Alta (7.5) | 1.3% | — | Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+6 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629. | |
| Modificada | Media (6.1) | 1.5% | — | JsoupNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCINetapp Oncommand Workflow Automation | 29/8/2022 | 17/6/2026 | jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks`… | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat UndertowNetapp Cloud Secure Agent+2 | 26/8/2022 | 17/6/2026 | A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks. | |
| Modificada | Media (6.1) | 1.7% | — | Apache ArtemisNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 23/8/2022 | 17/6/2026 | In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue. | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+14 | 5/8/2022 | 14/7/2026 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the… | |
| Modificada | Crítica (9.8) | 0.96% | — | Google-cloudstorage-commands Project Google-cloudstorage-commands | 25/7/2022 | 17/6/2026 | This affects all versions of package google-cloudstorage-commands. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Powerstore Command Line Interface | 21/7/2022 | 17/6/2026 | Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure. | |
| Modificada | Media (6.1) | 2.7% | 💥 PoC | Jqueryui Jquery UINetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+6 | 20/7/2022 | 17/6/2026 | jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input… | |
| Modificada | Media (6.5) | 1.4% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 19/7/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 1.4% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 19/7/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 1.3% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 19/7/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… |