Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1623 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.98%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.39 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.…
ModificadaAlta (7.5)3.4%—Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation2/10/20227/10/2026
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
ModificadaAlta (7.5)3.4%—Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation2/10/20227/10/2026
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
ModificadaAlta (7.8)0.19%—Dell Alienware UpdateDell Command UpdateDell Update2/9/202217/6/2026
Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.
ModificadaMedia (4.9)0.89%—Redhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Single Sign-on+51/9/202217/6/2026
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
ModificadaAlta (8.1)1.9%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
ModificadaAlta (7.5)1.7%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.
ModificadaMedia (5.5)0.21%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
ModificadaMedia (5.5)0.18%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.
ModificadaMedia (6.5)0.49%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465.
ModificadaMedia (6.5)0.41%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.
ModificadaMedia (6.5)0.41%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.
ModificadaAlta (7.8)0.22%—Dell Command | Integration Suite FOR System Center31/8/202217/6/2026
Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary write as system.
ModificadaAlta (7.5)1.6%—Redhat Openshift Application RuntimesRedhat Single Sign-onRedhat UndertowNetapp Active IQ Unified Manager+331/8/202217/6/2026
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet…
ModificadaAlta (7.5)1.3%—Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+631/8/202217/6/2026
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
ModificadaMedia (6.1)1.5%—JsoupNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCINetapp Oncommand Workflow Automation29/8/202217/6/2026
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks`…
ModificadaAlta (7.5)1.6%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat UndertowNetapp Cloud Secure Agent+226/8/202217/6/2026
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
ModificadaMedia (6.1)1.7%—Apache ArtemisNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation23/8/202217/6/2026
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
ModificadaCrítica (9.8)19%💥 PoCZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+145/8/202214/7/2026
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the…
ModificadaCrítica (9.8)0.96%—Google-cloudstorage-commands Project Google-cloudstorage-commands25/7/202217/6/2026
This affects all versions of package google-cloudstorage-commands.
ModificadaAlta (7.8)0.19%—Dell Powerstore Command Line Interface21/7/202217/6/2026
Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure.
ModificadaMedia (6.1)2.7%💥 PoCJqueryui Jquery UINetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+620/7/202217/6/2026
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input…
ModificadaMedia (6.5)1.4%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+119/7/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)1.4%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+119/7/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)1.3%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+119/7/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…