Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 20% | 💥 PoC | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+2 | 17/2/2023 | 17/6/2026 | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Media (6.5) | 90% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+2 | 3/2/2023 | 17/6/2026 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states… | |
| Modificada | Alta (7.1) | 0.28% | — | Linux KernelNetapp HCI Baseboard Management Controller | 17/1/2023 | 17/6/2026 | A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information. | |
| Modificada | Alta (7.8) | 0.30% | — | Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux | 13/1/2023 | 17/6/2026 | In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition. | |
| Analizada | Alta (7.8) | 0.43% | — | Netapp H410s FirmwareNetapp H410c FirmwareNetapp H700s FirmwareNetapp H500s Firmware+2 | 11/1/2023 | 1/9/2026 | There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as… | |
| Analizada | Alta (7.8) | 0.57% | — | Apple MacosNetapp HCI Compute NodeNeovimVIM+1 | 4/1/2023 | 24/9/2026 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | |
| Analizada | Alta (8.1) | 3.5% | — | Debian LinuxNetapp Active IQ Unified ManagerFasterxml Jackson-databindOracle Retail Merchandising System+1 | 26/12/2022 | 17/6/2026 | A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and… | |
| Modificada | Alta (7.5) | 17% | — | Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 23/12/2022 | 17/6/2026 | A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in… | |
| Modificada | Alta (8.6) | 0.54% | — | Netapp Oncommand Insight | 20/12/2022 | 17/6/2026 | OnCommand Insight versions 7.3.1 through 7.3.14 are susceptible to an authentication bypass vulnerability in the Data Warehouse component. | |
| Modificada | Alta (7.8) | 0.34% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames. | |
| Modificada | Alta (7.1) | 0.32% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink packet. | |
| Modificada | Alta (7.8) | 0.30% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from Wi-Fi management frames. | |
| Modificada | Alta (7.8) | 0.33% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames. | |
| Analizada | Alta (7.5) | 0.53% | — | CertifiNetapp E-series Performance AnalyzerNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI | 7/12/2022 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root… | |
| Modificada | Media (6.5) | 1.9% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+4 | 5/12/2022 | 17/6/2026 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or… | |
| Modificada | Crítica (9.8) | 4.7% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+5 | 5/12/2022 | 17/6/2026 | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and… | |
| Modificada | Alta (7.8) | 0.67% | — | VIMNetapp Ontap Select Deploy Administration Utility | 5/12/2022 | 17/6/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. | |
| Modificada | Alta (7.8) | 0.77% | 💥 PoC | Linux KernelFedoraproject FedoraNetapp H410c FirmwareNetapp H300s Firmware+4 | 27/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. | |
| Modificada | Alta (7) | 0.26% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 27/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event. | |
| Modificada | Media (6.4) | 0.71% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device. | |
| Modificada | Media (4.7) | 0.29% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call. | |
| Modificada | Alta (7) | 0.33% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb_device_open race condition that leads to a use-after-free. | |
| Modificada | Alta (7) | 0.31% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected. | |
| Analizada | Alta (7) | 0.33% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+2 | 25/11/2022 | 13/8/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops. |