Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.0% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption. | |
| Modificada | Alta (7.5) | 4.1% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation. | |
| Modificada | Alta (7.2) | 21% | 💥 Exploit | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+19 | 15/2/2021 | 17/6/2026 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | |
| Modificada | Media (5.5) | 1.8% | — | NettyDebian LinuxQuarkusOracle Banking Corporate Lending Process Management+9 | 8/2/2021 | 17/6/2026 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are… | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+20 | 26/1/2021 | 17/6/2026 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| Modificada | Media (5.9) | 3.0% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 20/1/2021 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of… | |
| Modificada | Media (4.2) | 1.4% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+1 | 20/1/2021 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client.… | |
| Modificada | Baja (3.7) | 2.3% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 20/1/2021 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client.… | |
| Modificada | Media (5.3) | 1.8% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+1 | 20/1/2021 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can… | |
| Modificada | Baja (3.8) | 1.6% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 20/1/2021 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Analizada | Alta (8.1) | 7.5% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Oncommand API ServicesNetapp Oncommand Insight+5 | 19/1/2021 | 24/7/2026 | A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Crítica (9.8) | 23% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 19/1/2021 | 17/6/2026 | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely. | |
| Modificada | Baja (3.3) | 0.92% | — | Google GuavaQuarkusOracle Commerce Guided SearchOracle Communications Cloud Native Core Network Slice Selection Function+9 | 10/12/2020 | 17/6/2026 | A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable… | |
| Modificada | Alta (7.8) | 1.1% | 💥 PoC | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+8 | 9/12/2020 | 17/6/2026 | A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. | |
| Modificada | Media (4.4) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 9/12/2020 | 17/6/2026 | A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24. | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Media (6.5) | 1.1% | — | InfinispanRedhat Data GridNetapp Active IQ Unified Manager | 3/12/2020 | 17/6/2026 | A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role. | |
| Modificada | Media (5.3) | 9.0% | — | Apache HttpclientQuarkusOracle Data IntegratorOracle JD Edwards Enterpriseone Orchestrator+13 | 2/12/2020 | 17/6/2026 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | |
| Modificada | Alta (7.5) | 4.4% | — | MIT Kerberos 5Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+7 | 6/11/2020 | 17/6/2026 | MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit. | |
| Modificada | Media (6.5) | 1.5% | — | Redhat WildflyRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+6 | 2/11/2020 | 17/6/2026 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a… | |
| Modificada | Media (4.9) | 1.8% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 21/10/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 21/10/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.4) | 1.9% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 21/10/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 21/10/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 21/10/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… |