Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1488 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.98%—IBM Cognos AnalyticsNetapp Oncommand Insight24/6/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
ModificadaAlta (8.1)3.8%—Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Oncommand Insight+102/6/202217/6/2026
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
ModificadaMedia (5.9)1.3%—Redhat IntegrationRedhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Undertow+424/5/202217/6/2026
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to…
ModificadaMedia (5.9)1.1%—Redhat FuseRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Single Sign-on+424/5/202217/6/2026
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to…
ModificadaMedia (6.5)3.2%💥 PoCVmware Spring FrameworkOracle Financial Services Crime AND Compliance Management StudioNetapp Cloud Secure AgentNetapp Oncommand Insight12/5/202217/6/2026
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
ModificadaMedia (5.3)2.0%💥 PoCVmware Spring FrameworkOracle Financial Services Crime AND Compliance Management StudioNetapp Active IQ Unified ManagerNetapp Brocade SAN Navigator+212/5/202217/6/2026
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
ModificadaAlta (7.8)0.48%—Insightsoftware Magnitude Simba Amazon Redshift Jdbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972.
ModificadaAlta (7.8)0.48%—Insightsoftware Magnitude Simba Amazon Athena Jdbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971.
ModificadaAlta (7.8)3.7%—Insightsoftware Magnitude Simba Amazon Redshift Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.
ModificadaAlta (7.8)0.37%—Insightsoftware Magnitude Simba Amazon Athena Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.
ModificadaAlta (7.3)83%💥 PoCSiemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+313/5/202217/6/2026
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the…
ModificadaMedia (5.4)0.69%—IBM Cognos AnalyticsNetapp Oncommand Insight22/4/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211240.
ModificadaMedia (4.3)0.92%—IBM Cognos AnalyticsNetapp Oncommand Insight22/4/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should not have access to. IBM X-Force ID: 209697.
ModificadaMedia (6.5)1.8%—IBM Cognos AnalyticsNetapp Oncommand Insight22/4/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings. IBM X-Force ID: 209693.
ModificadaMedia (5.4)0.97%—IBM Cognos AnalyticsNetapp Oncommand Insight22/4/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the…
ModificadaAlta (8.8)0.57%—IBM Cognos AnalyticsNetapp Oncommand Insight22/4/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.
ModificadaMedia (4.3)0.88%—IBM Cognos AnalyticsNetapp Oncommand Insight22/4/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.
ModificadaMedia (6.5)1.4%—IBM Cognos AnalyticsNetapp Oncommand Insight22/4/202217/6/2026
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
ModificadaMedia (5.3)2.8%—Oracle GraalvmOracle Java SENetapp Active IQ Unified ManagerNetapp Cloud Insights Acquisition Unit+1219/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows…
ModificadaMedia (6.3)79%—Oracle Mysql ClusterNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Snapcenter19/4/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication…
ModificadaMedia (6.3)79%—Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Snapcenter19/4/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication…
ModificadaBaja (2.9)1.7%—Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Snapcenter19/4/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication…
ModificadaBaja (2.9)1.8%—Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Snapcenter19/4/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication…
ModificadaBaja (2.9)1.7%—Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Snapcenter19/4/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication…
ModificadaMedia (6.3)3.0%—Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Snapcenter19/4/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication…
Orbitaley — Vulnerabilidades