Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.6)2.6%—Oracle JDKOracle JREDebian LinuxNetapp Active IQ Unified Manager+218/8/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
ModificadaCrítica (9.6)2.4%—Oracle JDKOracle JREDebian LinuxRedhat Satellite+228/8/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaCrítica (9.6)2.6%—Oracle JDKOracle JREDebian LinuxRedhat Satellite+228/8/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaCrítica (9.6)2.1%—Oracle JDKOracle JREDebian LinuxNetapp Active IQ Unified Manager+158/8/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaMedia (4.3)2.2%—Oracle JDKOracle JREDebian LinuxNetapp Active IQ Unified Manager+158/8/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (8.1)2.4%—Oracle JDKOracle JREDebian LinuxRedhat Satellite+238/8/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported version that is affected is Java SE: 8u131. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can…
ModificadaAlta (8.3)3.1%—Oracle JDKOracle JREDebian LinuxRedhat Enterprise Linux Desktop+218/8/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (7.5)3.3%—Oracle JDKOracle JREDebian LinuxRedhat Satellite+228/8/201717/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require…
ModificadaMedia (5.3)3.5%—Oracle JDKOracle JREOracle JrockitDebian Linux+248/8/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple…
ModificadaCrítica (9.8)7.5%—ZlibOpensuse LeapOpensuseDebian Linux+3523/5/201714/7/2026
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
ModificadaAlta (7.5)41%—ISC BindDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+812/1/201717/6/2026
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
ModificadaAlta (7.5)39%—ISC BindNetapp Data Ontap EdgeNetapp SolidfireNetapp Steelstore Cloud Integrated Storage+72/11/201617/6/2026
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
ModificadaCrítica (9.8)32%—OpensslPulsesecure ClientPulsesecure Steel Belted Radius3/3/201617/6/2026
The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large…
ModificadaMedia (5.9)82%💥 PoCOpensslPulsesecure ClientPulsesecure Steel Belted Radius1/3/201617/6/2026
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a…
ModificadaMedia (4.3)1.4%—Riverbed Steelapp Traffic Manager19/8/201417/6/2026
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.
ModificadaMedia (4.3)8.6%—Openbsd OpensshNetapp HCI Management NodeNetapp SolidfireNetapp Steelstore Cloud Integrated Storage+121/5/200716/6/2026
OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.
ModificadaAlta (7.5)1.8%—C.j. Steele TattleAI8/6/200516/6/2026
The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.
ModificadaAlta (10)2.2%—Steelid Thephototool23/11/200416/6/2026
SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.
ModificadaAlta (7.5)6.3%—Tomahawk Technologies Steelarrow11/4/200316/6/2026
Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding…
Orbitaley — Vulnerabilidades