Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 53% | 💥 Exploit | F5 NginxOpenrestyFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+9 | 1/6/2021 | 17/6/2026 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | |
| Modificada | Alta (7.7) | 3.1% | — | Redislabs RedisOracle Communications Operations MonitorSuse Linux EnterpriseDebian Linux | 15/6/2020 | 17/6/2026 | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which… | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (5.3) | 2.8% | — | Tcpdump LibpcapDebian LinuxOpensuse LeapOracle Communications Operations Monitor+7 | 3/10/2019 | 17/6/2026 | sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. | |
| Modificada | Crítica (9.8) | 18% | — | Haxx CurlFedoraproject FedoraOpensuse LeapNetapp Cloud Backup+13 | 16/9/2019 | 17/6/2026 | Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. | |
| Modificada | Crítica (9.8) | 7.5% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Steelstore+8 | 16/9/2019 | 17/6/2026 | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. | |
| Modificada | Alta (7.5) | 5.4% | — | PythonFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+6 | 6/9/2019 | 17/6/2026 | An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could… | |
| Modificada | Alta (7.2) | 24% | — | Redislabs RedisRedhat OpenstackRedhat Enterprise LinuxRedhat Enterprise Linux EUS+5 | 11/7/2019 | 17/6/2026 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a… | |
| Modificada | Alta (7.2) | 26% | — | Redislabs RedisRedhat OpenstackRedhat Software CollectionsRedhat Enterprise Linux+6 | 11/7/2019 | 17/6/2026 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond… | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Crítica (9.8) | 3.5% | — | SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+5 | 20/2/2019 | 17/6/2026 | SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. | |
| Modificada | Alta (7.8) | 1.8% | — | SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+5 | 6/2/2019 | 17/6/2026 | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. | |
| Modificada | Alta (7.5) | 4.3% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+3 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond… | |
| Modificada | Crítica (9.8) | 13% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+12 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent… | |
| Modificada | Alta (7.5) | 5.4% | 💥 PoC | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+6 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a… | |
| Modificada | Crítica (9.8) | 7.0% | — | Redislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack | 17/6/2018 | 17/6/2026 | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking. | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Redislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack | 17/6/2018 | 17/6/2026 | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | OpensslOracle Agile Engineering Data ManagementOracle Communications Application Session ControllerOracle Communications Eagle LNP Application Processor+3 | 4/5/2017 | 17/6/2026 | In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. | |
| Modificada | Media (6.5) | 2.7% | — | Oracle Communications Operations Monitor | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Communications Operations Monitor component in Oracle Communications Applications before 3.3.92.0.0 allows remote authenticated users to affect confidentiality via vectors related to Infrastructure. |