Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2306 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 74% | 💥 PoC | Netapp HCI Baseboard Management ControllerNetapp Active IQ Unified ManagerNetapp Bootstrap OSPowerdns Recursor+4 | 14/2/2024 | 17/6/2026 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an… | |
| Modificada | Alta (7.5) | 1.1% | — | ISC BindNetapp Active IQ Unified Manager | 13/2/2024 | 17/6/2026 | To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later… | |
| Modificada | Media (5.3) | 0.63% | — | ISC BindNetapp Active IQ Unified Manager | 13/2/2024 | 17/6/2026 | If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1. | |
| Modificada | Alta (7.5) | 1.2% | — | Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and… | |
| Modificada | Alta (7.5) | 1.2% | — | Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: | |
| Modificada | Crítica (10) | 2.4% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity ConnectionCisco Unified Contact Center Express+1 | 26/1/2024 | 17/6/2026 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could… | |
| Modificada | Crítica (9.8) | 1.00% | — | Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+11 | 19/1/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long… | |
| Modificada | Alta (7.5) | 1.4% | — | GnutlsFedoraproject FedoraNetapp Active IQ Unified ManagerDebian Linux | 16/1/2024 | 17/6/2026 | A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack. | |
| Modificada | Crítica (9.8) | 0.75% | — | Buy-addons Bazoom Magnifier | 5/1/2024 | 17/6/2026 | SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method. | |
| Modificada | Crítica (9.8) | 1.1% | — | Unifiedremote Unified Remote | 30/12/2023 | 17/6/2026 | Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint. | |
| Modificada | Media (5.4) | 1.2% | — | Apache Nifi | 27/11/2023 | 17/6/2026 | Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting. If an authenticated user, who is authorized to configure a JoltTransformJSON Processor, visits a crafted URL, then arbitrary JavaScript… | |
| Modificada | Media (5.4) | 0.46% | — | Cisco IP Dect 110 FirmwareCisco IP Dect 210 FirmwareCisco Unified IP Phone 6901 FirmwareCisco Unified SIP Phone 3905 Firmware | 21/11/2023 | 17/6/2026 | A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied… | |
| Modificada | Alta (7.8) | 57% | — | 7-zipNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 3/11/2023 | 17/6/2026 | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | |
| Modificada | Media (5.8) | 0.52% | — | Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Unified Threat DefenseCisco Meraki MX Security Appliance Firmware | 1/11/2023 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 9.5% | 💥 PoC | Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+1 | 1/11/2023 | 17/6/2026 | A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+2 | 27/10/2023 | 17/6/2026 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or… | |
| Modificada | Media (5.3) | 0.63% | — | UI Unifi Network Application | 25/10/2023 | 17/6/2026 | Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network.… | |
| Modificada | Crítica (9.8) | 78% | 💥 PoC | Haxx LibcurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+9 | 18/10/2023 | 17/6/2026 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be… | |
| Modificada | Media (5.5) | 0.28% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp H410c Firmware | 14/10/2023 | 17/6/2026 | An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.5) | 1.4% | — | LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraRedhat Enterprise Linux | 5/10/2023 | 17/6/2026 | LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 0.81% | — | Cisco Emergency ResponderCisco Prime Collaboration DeploymentCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+1 | 4/10/2023 | 17/6/2026 | A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is… | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosFedoraproject Fedora+10 | 21/9/2023 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | |
| Modificada | Media (5.9) | 1.9% | 💥 PoC | GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems EUS S390x+12 | 12/9/2023 | 17/6/2026 | A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or… | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraDebian LinuxMozilla Firefox+8 | 12/9/2023 | 17/6/2026 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) |