Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.3%💥 PoCLinux KernelFedoraproject FedoraRedhat Enterprise LinuxOracle Communications Cloud Native Core Binding Support Function+216/2/202217/6/2026
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
ModificadaAlta (7.1)1.7%—Linux KernelRedhat 3scaleRedhat Virtualization HostFedoraproject Fedora+1516/2/202217/6/2026
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality,…
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaMedia (5.5)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaMedia (6.5)0.97%—Jenkins Support Core15/2/202217/6/2026
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
ModificadaMedia (5.4)0.60%—Supportcandy7/2/202217/6/2026
The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
ModificadaAlta (8.8)0.61%—Supportcandy7/2/202217/6/2026
The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies)…
ModificadaMedia (6.1)1.2%💥 ExploitSupportcandy7/2/202217/6/2026
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.5)0.53%—Supportcandy7/2/202217/6/2026
The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.
ModificadaAlta (7.5)1.2%—Supportcandy7/2/202217/6/2026
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions may be affected as well.
ModificadaMedia (4.8)0.65%—Benbodhi SVG Support1/2/202217/6/2026
The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (5.5)0.53%—Linux KernelOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure FunctionOracle Communications Cloud Native Core Policy31/1/202217/6/2026
A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of service.
ModificadaMedia (5.5)0.28%—HP Support Assistant28/1/202217/6/2026
Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.
ModificadaAlta (7)0.31%—Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+1118/1/202217/6/2026
A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This…
ModificadaCrítica (9.8)4.3%—GNU GlibcOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+414/1/202217/6/2026
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a…
ModificadaBaja (3.5)0.37%—Linux KernelOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure FunctionOracle Communications Cloud Native Core Policy25/12/202117/6/2026
In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.
AnalizadaAlta (7.5)3.6%💥 PoCLinux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+2225/12/20215/8/2026
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
ModificadaAlta (7.1)2.7%—LxmlFedoraproject FedoraDebian LinuxNetapp Solidfire+713/12/202117/6/2026
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade…
ModificadaMedia (6.5)2.9%—NettyQuarkusNetapp Oncommand Workflow AutomationNetapp Snapcenter+149/12/202117/6/2026
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not…
ModificadaCrítica (9.8)18%—Mozilla NSSMozilla NSS ESRNetapp Cloud BackupNetapp E-series Santricity OS Controller+68/12/202117/6/2026
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate…
ModificadaAlta (7.5)3.5%—Zohocorp Manageengine Supportcenter Plus30/11/202117/6/2026
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.