Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 50% | 💥 PoC | OpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+12 | 14/12/2021 | 17/6/2026 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as… | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Media (5.5) | 0.29% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Space Management | 13/12/2021 | 17/6/2026 | IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438. | |
| Modificada | Crítica (9.8) | 18% | — | Mozilla NSSMozilla NSS ESRNetapp Cloud BackupNetapp E-series Santricity OS Controller+6 | 8/12/2021 | 17/6/2026 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate… | |
| Modificada | Alta (7.8) | 0.52% | — | Linux KernelNetapp Cloud BackupNetapp H410c FirmwareNetapp H300s Firmware+6 | 8/12/2021 | 17/6/2026 | The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c. | |
| Modificada | Crítica (9.8) | 1.9% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community. | |
| Modificada | Media (6.5) | 1.5% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule. | |
| Modificada | Crítica (9.8) | 3.0% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker. | |
| Modificada | Alta (8.8) | 2.4% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application. | |
| Modificada | Alta (8.8) | 1.8% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation. | |
| Modificada | Media (6.5) | 1.3% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access. | |
| Modificada | Alta (8.8) | 2.3% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user. | |
| Modificada | Alta (7.8) | 0.52% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM. | |
| Modificada | Crítica (9.8) | 1.9% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak. | |
| Modificada | Crítica (9.8) | 3.4% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user… | |
| Modificada | Alta (7.8) | 0.45% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation. | |
| Modificada | Crítica (9.8) | 6.2% | — | Kaseya Unitrends Backup | 6/12/2021 | 17/6/2026 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls. | |
| Modificada | Media (5.4) | 0.57% | — | Backupbliss Backup Migration | 19/11/2021 | 17/6/2026 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions. | |
| Modificada | Media (4.6) | 0.69% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+11 | 17/11/2021 | 17/6/2026 | In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). | |
| Modificada | Media (6.7) | 0.55% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+7 | 17/11/2021 | 17/6/2026 | In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value. | |
| Modificada | Crítica (9.8) | 3.6% | — | BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+8 | 15/11/2021 | 17/6/2026 | An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input. | |
| Modificada | Media (5.5) | 0.43% | — | BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+8 | 15/11/2021 | 17/6/2026 | A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input. | |
| Modificada | Media (5.5) | 0.41% | — | BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+8 | 15/11/2021 | 17/6/2026 | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input. | |
| Modificada | Media (5.3) | 0.62% | — | BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+8 | 15/11/2021 | 17/6/2026 | An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that | |
| Modificada | Media (5.5) | 0.41% | — | BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+8 | 15/11/2021 | 17/6/2026 | A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given |