Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 61% | ⚠ Explotación activa💥 PoC | AMI Megarac Sp-xNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+6 | 11/3/2025 | 17/6/2026 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatDebian LinuxNetapp Bootstrap OS | 10/3/2025 | 17/6/2026 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1… | |
| Analizada | Alta (7.1) | 22% | — | VIMNetapp HCI Compute Node | 3/3/2025 | 17/6/2026 | Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin uses the ":read" ex command line to append below the cursor position, however the is not sanitized and… | |
| Modificada | Alta (7.7) | 0.39% | — | Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | |
| Modificada | Crítica (9.8) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. | |
| Analizada | Media (4.2) | 0.24% | — | VIMNetapp HCI Compute Node | 18/2/2025 | 17/6/2026 | Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a… | |
| Modificada | Media (6.8) | 7.7% | 💥 PoC | Openbsd OpensshNetapp Active IQ Unified ManagerNetapp OntapRedhat Openshift Container Platform+2 | 18/2/2025 | 2/9/2026 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be… | |
| Analizada | Baja (2.4) | 0.54% | — | VIMNetapp Bootstrap OS | 12/2/2025 | 17/6/2026 | A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this… | |
| Analizada | Baja (2.3) | 0.72% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (6.3) | 0.80% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The… | |
| Analizada | Alta (7.5) | 2.2% | — | NettyNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 10/2/2025 | 17/6/2026 | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.… | |
| Analizada | Alta (7.3) | 1.3% | — | Netapp HCI Baseboard Management ControllerNetapp HCI H610s FirmwareNetapp HCI H610c FirmwareNetapp HCI H615c Firmware+4 | 5/2/2025 | 17/6/2026 | When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow. | |
| Modificada | Alta (7) | 1.3% | — | Haxx CurlNetapp Bootstrap OSNetapp H300s FirmwareNetapp H410c Firmware+3 | 5/2/2025 | 17/6/2026 | libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve. | |
| Analizada | Baja (3.4) | 0.69% | — | Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+12 | 5/2/2025 | 17/6/2026 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
| Analizada | Media (6.8) | 0.90% | — | Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation | 4/2/2025 | 17/6/2026 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | |
| Analizada | Alta (7) | 67% | ⚠ Explotación activa💥 PoC | Netapp Active IQ Unified Manager7-zip | 25/1/2025 | 17/6/2026 | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific… | |
| Analizada | Media (4.8) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+7 | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM… | |
| Analizada | Media (4.9) | 0.96% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Analizada | Media (5.5) | 0.28% | — | VIMNetapp HCI Compute Node Firmware | 20/1/2025 | 17/6/2026 | Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by… | |
| Analizada | Media (5.5) | 0.37% | — | NeovimVIMNetapp Bootstrap OS | 13/1/2025 | 17/6/2026 | When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before opening… | |
| Analizada | Crítica (9.1) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+5 | 23/12/2024 | 17/6/2026 | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible. | |
| Modificada | Crítica (9.8) | 9.0% | — | Apache TomcatNetapp Bootstrap OS | 20/12/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though… | |
| Modificada | Alta (7.5) | 0.92% | — | ES Iperf3Netapp Ontap 9Netapp HCI Compute Node | 18/12/2024 | 17/6/2026 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | |
| Modificada | Media (5.3) | 1.9% | — | Apache TomcatNetapp Bootstrap OS | 17/12/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was… | |
| Modificada | Crítica (9.8) | 32% | 💥 PoC | Apache TomcatNetapp Bootstrap OS | 17/12/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through… |