Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.28% | — | Oracle ZFS Storage Appliance KIT | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS… | |
| Modificada | Media (4.7) | 0.53% | — | Microsoft Azure Storage BlobsMicrosoft Azure Storage Queue | 12/7/2022 | 17/6/2026 | Azure Storage Library Information Disclosure Vulnerability | |
| Modificada | Crítica (9.3) | 1.3% | — | Purestorage Pure Swagger | 11/7/2022 | 17/6/2026 | The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.8) | 1.0% | — | Cloud Mobility FOR Dell EMC Storage | 7/7/2022 | 17/6/2026 | Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a critical issue; so Dell recommends customers to upgrade at the earliest opportunity. | |
| Modificada | Alta (7.5) | 2.6% | — | Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+4 | 7/7/2022 | 17/6/2026 | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good… | |
| Modificada | Baja (2.7) | 1.3% | — | Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+3 | 7/7/2022 | 17/6/2026 | In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario. | |
| Modificada | Crítica (9.8) | 1.3% | — | Purestorage Purity//faPurestorage Purity//fb | 23/6/2022 | 17/6/2026 | Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to possibly exposed… | |
| Modificada | Alta (8.8) | 1.2% | — | Purestorage Purity//faPurestorage Purity//fb | 23/6/2022 | 17/6/2026 | Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to a privilege… | |
| Modificada | Alta (8.8) | 1.2% | — | Purestorage Purity//faPurestorage Purity//fb | 23/6/2022 | 17/6/2026 | Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to a privilege… | |
| Modificada | Media (4.3) | 1.3% | — | Haxx CurlNetapp HCI Bootstrap OSNetapp Clustered Data OntapNetapp Solidfire, Enterprise SDS & HCI Storage Node+6 | 2/6/2022 | 17/6/2026 | Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by… | |
| Modificada | Alta (7.5) | 2.7% | — | Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+8 | 2/6/2022 | 17/6/2026 | libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation. | |
| Modificada | Alta (7.5) | 2.5% | — | Haxx CurlNetapp HCI Bootstrap OSNetapp Clustered Data OntapNetapp Solidfire, Enterprise SDS & HCI Storage Node+6 | 2/6/2022 | 17/6/2026 | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into… | |
| Modificada | Media (5.3) | 2.7% | — | Haxx CurlNetapp HCI Bootstrap OSNetapp Clustered Data OntapNetapp Solidfire, Enterprise SDS & HCI Storage Node+7 | 2/6/2022 | 17/6/2026 | libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided, a more… | |
| Modificada | Media (6.5) | 3.8% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp HCI Bootstrap OS+9 | 2/6/2022 | 17/6/2026 | A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. | |
| Modificada | Alta (7.5) | 3.2% | — | Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+8 | 2/6/2022 | 17/6/2026 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. | |
| Modificada | Media (5.7) | 1.8% | — | Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+8 | 2/6/2022 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers. | |
| Modificada | Alta (8.1) | 2.2% | — | Haxx CurlDebian LinuxNetapp Clustered Data OntapNetapp Solidfire & HCI Management Node+8 | 26/5/2022 | 17/6/2026 | An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S),… | |
| Modificada | Crítica (9.8) | 3.1% | 💥 PoC | Rubyonrails Active StorageDebian Linux | 26/5/2022 | 17/6/2026 | A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments. | |
| Modificada | Alta (7.5) | 2.9% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorNetapp E-series Santricity OS Controller+13 | 25/5/2022 | 17/6/2026 | An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. | |
| Modificada | Crítica (9.1) | 0.70% | — | IBM Elastic Storage SystemIBM Spectrum Scale | 24/5/2022 | 17/6/2026 | A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600. | |
| Modificada | Alta (8.8) | 0.69% | — | Jenkins Storage Configs | 17/5/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local XML file (e.g., archived artifacts) that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery. | |
| Modificada | Media (4.4) | 0.26% | — | Intel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x FirmwareIntel Optane SSD P5800x FirmwareIntel Optane Memory H20 With Solid State Storage Firmware+3 | 12/5/2022 | 17/6/2026 | Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow an privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.6) | 0.27% | — | Intel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x FirmwareIntel Optane SSD P5800x FirmwareIntel Optane Memory H20 With Solid State Storage Firmware+3 | 12/5/2022 | 17/6/2026 | Sensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access. | |
| Modificada | Media (6.8) | 0.26% | — | Intel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x FirmwareIntel Optane SSD P5800x FirmwareIntel Optane Memory H20 With Solid State Storage Firmware+3 | 12/5/2022 | 17/6/2026 | Exposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products may allow an unauthenticated user to potentially enable information disclosure or escalation of privilege via physical access. | |
| Modificada | Media (4.7) | 0.15% | — | Intel Optane SSD DC P4800x FirmwareIntel Optane SSD DC P4801x FirmwareIntel Optane SSD P5800x FirmwareIntel Optane Memory H20 With Solid State Storage Firmware+3 | 12/5/2022 | 17/6/2026 | Race condition within a thread in firmware for some Intel(R) Optane(TM) SSD and Intel(R) SSD DC Products may allow a privileged user to potentially enable denial of service via local access. |