Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)60%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+2211/6/202117/6/2026
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at…
ModificadaBaja (3.1)4.5%—Haxx CurlDebian LinuxFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+811/6/202117/6/2026
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data…
ModificadaMedia (5.3)3.0%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+1811/6/202117/6/2026
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if…
ModificadaCrítica (9.8)82%—Debian LinuxISC BindSiemens Sinec Infrastructure Network ServicesNetapp Active IQ Unified Manager+1029/4/202117/6/2026
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured…
ModificadaAlta (7.5)11%—Debian LinuxISC BindFedoraproject FedoraNetapp Active IQ Unified Manager+1229/4/202117/6/2026
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw…
ModificadaMedia (6.5)6.0%—ISC BindDebian LinuxFedoraproject FedoraSiemens Sinec Infrastructure Network Services+1129/4/202117/6/2026
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR…
ModificadaBaja (3.7)3.1%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+71/4/202117/6/2026
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server…
ModificadaMedia (5.3)5.3%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+81/4/202117/6/2026
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP…
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaMedia (5.3)3.6%—Npmjs Hosted-git-infoSiemens Sinec Infrastructure Network Services23/3/202117/6/2026
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
ModificadaAlta (7.5)4.7%—Ssri Project SsriOracle GraalvmSiemens Sinec Infrastructure Network Services12/3/202117/6/2026
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
ModificadaAlta (7.5)37%—Nodejs Node.jsFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+93/3/202117/6/2026
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof…
ModificadaAlta (7.5)77%—Nodejs Node.jsFedoraproject FedoraNetapp E-series Performance AnalyzerOracle Graalvm+53/3/202117/6/2026
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new…
ModificadaAlta (8.1)64%—ISC BindDebian LinuxFedoraproject FedoraSiemens Sinec Infrastructure Network Services+317/2/202117/6/2026
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or…
ModificadaMedia (6.5)16%💥 PoCNodejs Node.jsDebian LinuxFedoraproject FedoraOracle Graalvm+16/1/202117/6/2026
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.
ModificadaAlta (8.1)9.1%—Nodejs Node.jsDebian LinuxFedoraproject FedoraOracle Graalvm+16/1/202117/6/2026
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an…
ModificadaAlta (7.5)4.6%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1314/12/202017/6/2026
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
ModificadaAlta (7.5)9.8%—Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+1814/12/202017/6/2026
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
ModificadaBaja (3.7)3.9%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1814/12/202017/6/2026
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
ModificadaAlta (7.5)3.8%—Haxx LibcurlSiemens Sinec Infrastructure Network ServicesDebian LinuxOracle Communications Cloud Native Core Policy+114/12/202017/6/2026
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
ModificadaAlta (7.8)1.3%—Haxx CurlDebian LinuxFujitsu M10-1 FirmwareFujitsu M10-4 Firmware+614/12/202017/6/2026
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
ModificadaAlta (7.5)3.5%—Haxx CurlSiemens Simatic TIM 1531 IRC FirmwareDebian LinuxSiemens Sinec Infrastructure Network Services+114/12/202017/6/2026
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
ModificadaMedia (5.9)7.1%💥 PoCOpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaCrítica (9.8)69%—Y18n Project Y18nOracle GraalvmSiemens Sinec Infrastructure Network Services17/11/202017/6/2026
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
ModificadaMedia (5.5)1.0%—SqliteCanonical Ubuntu LinuxApple IcloudApple Ipados+1227/6/202017/6/2026
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Orbitaley — Vulnerabilidades