Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.88% | — | ISC BindNetapp Active IQ Unified ManagerNetapp H500s FirmwareNetapp H700s Firmware+3 | 21/6/2023 | 17/6/2026 | A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and… | |
| Modificada | Alta (7.5) | 3.8% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of… | |
| Modificada | Alta (7.8) | 0.53% | 💥 PoC | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 16/6/2023 | 17/6/2026 | An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation. | |
| Modificada | Alta (7.8) | 0.44% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+3 | 5/6/2023 | 17/6/2026 | A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). | |
| Modificada | Alta (7.5) | 1.9% | — | OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+7 | 30/5/2023 | 17/6/2026 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. | |
| Modificada | Media (4.7) | 0.19% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+3 | 26/5/2023 | 17/6/2026 | There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. | |
| Modificada | Alta (7.8) | 0.49% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+3 | 15/5/2023 | 17/6/2026 | An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.5) | 2.4% | 💥 PoC | Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+4 | 25/4/2023 | 17/6/2026 | The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the… | |
| Modificada | Media (4.4) | 0.22% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+4 | 25/4/2023 | 17/6/2026 | A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. | |
| Modificada | Alta (7.8) | 0.29% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 24/4/2023 | 17/6/2026 | The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. | |
| Modificada | Media (5.5) | 0.41% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware | 24/4/2023 | 17/6/2026 | An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem)… | |
| Modificada | Alta (7.8) | 0.27% | — | Linux KernelNetapp H300s FirmwareNetapp H410c FirmwareNetapp H410s Firmware+2 | 31/3/2023 | 17/6/2026 | hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation. | |
| Modificada | Alta (7) | 0.28% | — | Linux KernelDebian LinuxNetapp A700s FirmwareNetapp 8300 Firmware+8 | 27/3/2023 | 17/6/2026 | In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing… | |
| Modificada | Alta (7.1) | 17% | — | Redhat Enterprise LinuxLinux KernelNetapp H500s FirmwareNetapp H700s Firmware+5 | 27/3/2023 | 17/9/2026 | A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service. | |
| Analizada | Alta (7.8) | 7.9% | ⚠ Explotación activa💥 Exploit | Debian LinuxNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+4 | 22/3/2023 | 17/6/2026 | A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on… | |
| Analizada | Media (4.7) | 0.33% | — | Debian LinuxLinux KernelNetapp H300s FirmwareNetapp H500s Firmware+3 | 25/2/2023 | 17/6/2026 | In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device. | |
| Analizada | Alta (7.8) | 0.43% | — | Netapp H410s FirmwareNetapp H410c FirmwareNetapp H700s FirmwareNetapp H500s Firmware+2 | 11/1/2023 | 1/9/2026 | There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as… | |
| Modificada | Alta (7.8) | 0.34% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames. | |
| Modificada | Alta (7.1) | 0.32% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink packet. | |
| Modificada | Alta (7.8) | 0.30% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from Wi-Fi management frames. | |
| Modificada | Alta (7.8) | 0.33% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames. | |
| Modificada | Alta (7.8) | 0.77% | 💥 PoC | Linux KernelFedoraproject FedoraNetapp H410c FirmwareNetapp H300s Firmware+4 | 27/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. | |
| Modificada | Alta (7) | 0.26% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 27/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event. | |
| Modificada | Media (6.4) | 0.71% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device. | |
| Modificada | Media (4.7) | 0.29% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call. |