Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.26%—Intel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r FirmwareIntel Xeon Gold 5220r FirmwareIntel Xeon Gold 6208u Firmware+66912/5/202217/6/2026
Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
ModificadaAlta (7.8)0.26%—Intel Xeon E-2386g FirmwareIntel Xeon E-2374g FirmwareIntel Xeon E-2314 FirmwareIntel Xeon E-2334 Firmware+22912/5/202217/6/2026
Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
ModificadaMedia (6.7)0.26%—Intel Xeon E-2386g FirmwareIntel Xeon E-2374g FirmwareIntel Xeon E-2314 FirmwareIntel Xeon E-2334 Firmware+18912/5/202217/6/2026
Unintended intermediary in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
ModificadaAlta (7.5)2.5%—OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+223/5/202217/6/2026
The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without…
ModificadaMedia (5.9)1.1%—OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+223/5/202217/6/2026
The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the…
ModificadaMedia (5.3)1.2%—OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+223/5/202217/6/2026
The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that…
ModificadaAlta (7.3)83%💥 PoCSiemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+313/5/202217/6/2026
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the…
ModificadaAlta (7.5)73%💥 PoCOpensslDebian LinuxNetapp Cloud Volumes Ontap MediatorNetapp Clustered Data Ontap+915/3/202217/6/2026
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded…
ModificadaMedia (4.6)0.25%—Intel Active Management Technology Software Development KITIntel Setup AND Configuration SoftwareIntel Management Engine Bios ExtensionIntel Core I3 Firmware+1769/2/202217/6/2026
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical…
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6769/2/202217/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.6)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.6)0.32%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.2)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.7)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.5)50%💥 PoCOpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+1214/12/202117/6/2026
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as…
ModificadaAlta (7)2.5%💥 PoCOpenbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+826/9/202114/7/2026
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of…
AnalizadaAlta (7)0.30%—Netapp Solidfire Baseboard Management ControllerLinux KernelFedoraproject FedoraDebian Linux+133/9/202113/8/2026
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
AnalizadaAlta (7.8)79%⚠ Explotación activa💥 ExploitNetapp C400 FirmwareNetapp C250 FirmwareNetapp H410c FirmwareNetapp H300s Firmware+177/7/202117/6/2026
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
ModificadaAlta (7.8)0.79%💥 PoCLinux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+826/5/202117/6/2026
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
ModificadaAlta (7)1.0%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management Node+1126/5/202117/6/2026
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
ModificadaMedia (6.1)1.1%—GNU WgetBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+229/4/202117/6/2026
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
ModificadaCrítica (9.8)82%—Debian LinuxISC BindSiemens Sinec Infrastructure Network ServicesNetapp Active IQ Unified Manager+1029/4/202117/6/2026
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured…
ModificadaAlta (7.5)11%—Debian LinuxISC BindFedoraproject FedoraNetapp Active IQ Unified Manager+1229/4/202117/6/2026
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw…
Orbitaley — Vulnerabilidades