Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2520 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)5.8%—Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+1323/11/202217/6/2026
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
ModificadaAlta (7.5)41%—Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+1323/11/202217/6/2026
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
ModificadaAlta (8.8)1.3%—LibtiffNetapp Active IQ Unified ManagerDebian LinuxApple Safari+313/11/202217/6/2026
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name…
ModificadaAlta (8.1)2.4%—Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+59/11/202210/8/2026
Netlogon RPC Elevation of Privilege Vulnerability
ModificadaAlta (7.2)4.1%—Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+59/11/202210/8/2026
Windows Kerberos Elevation of Privilege Vulnerability
ModificadaAlta (8.1)2.5%—Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+59/11/202210/8/2026
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
ModificadaAlta (7.5)2.7%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+59/11/202217/6/2026
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote…
ModificadaMedia (6.5)53%—Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+27/11/202217/6/2026
handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (6.5)52%—Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+27/11/202217/6/2026
handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaAlta (7.5)22%—Linux KernelNetapp Active IQ Unified ManagerNetapp H300s FirmwareNetapp H500s Firmware+34/11/202217/6/2026
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by…
ModificadaAlta (7.5)91%💥 PoCOpensslFedoraproject FedoraNetapp Clustered Data OntapNodejs Node.js1/11/202217/6/2026
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite…
ModificadaCrítica (9.8)3.4%💥 PoCVmware Spring SecurityNetapp Active IQ Unified Manager31/10/202217/6/2026
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and…
ModificadaAlta (8.1)1.1%—Vmware Spring SecurityNetapp Active IQ Unified Manager31/10/202217/6/2026
Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a…
ModificadaAlta (8.1)2.9%—Haxx CurlFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+529/10/202217/6/2026
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only…
ModificadaAlta (7.5)1.3%—VIMFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager26/10/202217/6/2026
A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue.…
ModificadaAlta (7.5)2.5%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraNetapp H300s Firmware+824/10/202217/6/2026
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
ModificadaAlta (7)0.87%—Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+321/10/202217/6/2026
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.…
ModificadaMedia (6.5)1.1%—LibtiffNetapp Active IQ Unified ManagerDebian Linux21/10/202217/6/2026
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
ModificadaMedia (6.5)1.0%—LibtiffNetapp Active IQ Unified ManagerDebian Linux21/10/202217/6/2026
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
ModificadaMedia (6.5)1.0%—LibtiffNetapp Active IQ Unified ManagerDebian Linux21/10/202217/6/2026
LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
ModificadaMedia (6.5)1.0%—LibtiffNetapp Active IQ Unified ManagerDebian Linux21/10/202217/6/2026
LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.
ModificadaMedia (6.5)1.0%—LibtiffNetapp Active IQ Unified ManagerDebian Linux21/10/202217/6/2026
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
ModificadaAlta (8.1)0.75%—Netapp Clustered Data Ontap19/10/202217/6/2026
Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period.
ModificadaMedia (6.5)1.3%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)1.3%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…