Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 5.8% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. | |
| Modificada | Alta (7.5) | 41% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. | |
| Modificada | Alta (8.8) | 1.3% | — | LibtiffNetapp Active IQ Unified ManagerDebian LinuxApple Safari+3 | 13/11/2022 | 17/6/2026 | A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name… | |
| Modificada | Alta (8.1) | 2.4% | — | Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+5 | 9/11/2022 | 10/8/2026 | Netlogon RPC Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 4.1% | — | Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+5 | 9/11/2022 | 10/8/2026 | Windows Kerberos Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.1) | 2.5% | — | Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+5 | 9/11/2022 | 10/8/2026 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 2.7% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+5 | 9/11/2022 | 17/6/2026 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote… | |
| Modificada | Media (6.5) | 53% | — | Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 7/11/2022 | 17/6/2026 | handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Media (6.5) | 52% | — | Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 7/11/2022 | 17/6/2026 | handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Alta (7.5) | 22% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp H300s FirmwareNetapp H500s Firmware+3 | 4/11/2022 | 17/6/2026 | The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by… | |
| Modificada | Alta (7.5) | 91% | 💥 PoC | OpensslFedoraproject FedoraNetapp Clustered Data OntapNodejs Node.js | 1/11/2022 | 17/6/2026 | A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite… | |
| Modificada | Crítica (9.8) | 3.4% | 💥 PoC | Vmware Spring SecurityNetapp Active IQ Unified Manager | 31/10/2022 | 17/6/2026 | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and… | |
| Modificada | Alta (8.1) | 1.1% | — | Vmware Spring SecurityNetapp Active IQ Unified Manager | 31/10/2022 | 17/6/2026 | Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a… | |
| Modificada | Alta (8.1) | 2.9% | — | Haxx CurlFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+5 | 29/10/2022 | 17/6/2026 | curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only… | |
| Modificada | Alta (7.5) | 1.3% | — | VIMFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager | 26/10/2022 | 17/6/2026 | A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue.… | |
| Modificada | Alta (7.5) | 2.5% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraNetapp H300s Firmware+8 | 24/10/2022 | 17/6/2026 | In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. | |
| Modificada | Alta (7) | 0.87% | — | Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+3 | 21/10/2022 | 17/6/2026 | A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.… | |
| Modificada | Media (6.5) | 1.1% | — | LibtiffNetapp Active IQ Unified ManagerDebian Linux | 21/10/2022 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191. | |
| Modificada | Media (6.5) | 1.0% | — | LibtiffNetapp Active IQ Unified ManagerDebian Linux | 21/10/2022 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191. | |
| Modificada | Media (6.5) | 1.0% | — | LibtiffNetapp Active IQ Unified ManagerDebian Linux | 21/10/2022 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125. | |
| Modificada | Media (6.5) | 1.0% | — | LibtiffNetapp Active IQ Unified ManagerDebian Linux | 21/10/2022 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b. | |
| Modificada | Media (6.5) | 1.0% | — | LibtiffNetapp Active IQ Unified ManagerDebian Linux | 21/10/2022 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191. | |
| Modificada | Alta (8.1) | 0.75% | — | Netapp Clustered Data Ontap | 19/10/2022 | 17/6/2026 | Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period. | |
| Modificada | Media (6.5) | 1.3% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 18/10/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 1.3% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 18/10/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… |