Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.28% | — | VIMNetapp HCI Compute Node Firmware | 20/1/2025 | 17/6/2026 | Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by… | |
| Analizada | Media (5.5) | 0.37% | — | NeovimVIMNetapp Bootstrap OS | 13/1/2025 | 17/6/2026 | When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before opening… | |
| Aplazada | Alta (7.5) | 0.40% | — | Lenderd 1003 Mortgage ApplicationAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in 8blocks 1003 Mortgage Application 1003-mortgage-application allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 1003 Mortgage Application: from n/a through <= 1.87. | |
| Aplazada | Media (4.3) | 0.33% | — | Lenderd 1003 Mortgage ApplicationAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in 8blocks 1003 Mortgage Application 1003-mortgage-application allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1003 Mortgage Application: from n/a through <= 1.87. | |
| Aplazada | Alta (7.5) | 0.61% | — | Service Shogun ACH Invoice APPAI | 7/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice App ach-invoice-app allows PHP Local File Inclusion.This issue affects Ach Invoice App: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.34% | — | Farhan Noor Applyonline Application Form Builder AND ManagerAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline – Application Form Builder and Manager: from n/a through 2.5.3. | |
| Analizada | Crítica (9.1) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+5 | 23/12/2024 | 17/6/2026 | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible. | |
| Modificada | Crítica (9.8) | 9.0% | — | Apache TomcatNetapp Bootstrap OS | 20/12/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though… | |
| Modificada | Alta (7.5) | 0.92% | — | ES Iperf3Netapp Ontap 9Netapp HCI Compute Node | 18/12/2024 | 17/6/2026 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | |
| Aplazada | Alta (8.7) | 0.70% | — | Oppo Store APPAI | 18/12/2024 | 17/6/2026 | In OPPO Store APP, there's a possible escalation of privilege due to improper input validation. | |
| Modificada | Media (5.3) | 1.9% | — | Apache TomcatNetapp Bootstrap OS | 17/12/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was… | |
| Modificada | Crítica (9.8) | 32% | 💥 PoC | Apache TomcatNetapp Bootstrap OS | 17/12/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Binarycarpenter Launchpage.app ImporterAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BinaryCarpenter LaunchPage.app Importer launchpage-app-importer allows SQL Injection.This issue affects LaunchPage.app Importer: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Menlo On-premise ApplianceAI | 14/12/2024 | 17/6/2026 | In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpmobile APPAI | 13/12/2024 | 17/6/2026 | The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Modificada | Baja (3.4) | 1.3% | — | Haxx CurlNetapp OntapNetapp Ontap Select Deploy Administration UtilityNetapp H610c Firmware+7 | 11/12/2024 | 17/6/2026 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either… | |
| Aplazada | Media (4.2) | 0.24% | — | Redhat Single Sign ONAIRedhat Jboss Enterprise Application PlatformAIRedhat Oidc ClientAI | 9/12/2024 | 4/8/2026 | A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a… | |
| Modificada | Crítica (9.8) | 1.3% | — | PHPNetapp Ontap | 22/11/2024 | 17/6/2026 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write. | |
| Modificada | Media (6) | 0.55% | — | QemuNetapp HCI Compute Node | 14/11/2024 | 17/6/2026 | A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of… | |
| Analizada | Crítica (9.8) | 1.3% | — | Gnome GlibDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Tools | 11/11/2024 | 17/6/2026 | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. | |
| Analizada | Media (4.8) | 0.23% | — | IBM Websphere Application Server | 11/11/2024 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.3) | 0.36% | — | Netapp Storagegrid | 8/11/2024 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash. | |
| Analizada | Media (6.1) | 0.46% | — | Redhat Codeready StudioRedhat Jboss Enterprise Application PlatformRedhat Openstack PlatformRedhat Single Sign-on+1 | 7/11/2024 | 17/6/2026 | A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS)… | |
| Modificada | Alta (7.5) | 1.7% | — | Apache TomcatNetapp Ontap Tools | 7/11/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35… | |
| Analizada | Media (4.8) | 0.37% | — | Nsqua Simply Schedule Appointments | 5/11/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed |