Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)53%—Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+27/11/202217/6/2026
handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (6.5)52%—Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+27/11/202217/6/2026
handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaAlta (7.8)0.38%—Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp HCI Management Node+220/8/202017/6/2026
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
ModificadaAlta (7.8)0.46%—Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp Smi-s Provider+120/8/202017/6/2026
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
ModificadaCrítica (9.8)2.0%—SnmpttDebian Linux16/8/202017/6/2026
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
ModificadaMedia (6.5)2.3%—Net-snmpOracle ZFS Storage Appliance KIT25/6/202017/6/2026
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.
ModificadaAlta (7.5)0.72%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
ModificadaMedia (5.4)0.56%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.
ModificadaAlta (7.5)1.4%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.
ModificadaAlta (7.5)1.5%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.
ModificadaAlta (8.8)0.51%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
ModificadaAlta (7.5)2.2%—Minisnmpd Project Minisnmpd4/2/202017/6/2026
A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a denial of service. To trigger this vulnerability, an attacker needs to simply initiate multiple connections to the…
ModificadaAlta (8.2)2.6%—Minisnmpd Project Minisnmpd4/2/202017/6/2026
An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which can result in sensitive information disclosure and Denial Of Service. In order to trigger this vulnerability, an attacker…
ModificadaCrítica (9.1)2.4%—Minisnmpd Project Minisnmpd4/2/202017/6/2026
An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To trigger this vulnerability, an attacker…
ModificadaMedia (6.7)0.34%—Intel Snmp Subagent Stand-alone17/1/202017/6/2026
Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)23%💥 ExploitComputerlab Maple Computer WBT Snmp Administrator17/7/201917/6/2026
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.
ModificadaAlta (7.5)3.6%—Net-snmpNetapp Cloud BackupNetapp Hyper Converged InfrastructureNetapp Storagegrid Webscale+38/10/201817/6/2026
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (6.5)18%💥 ExploitNet-snmpDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+68/10/201817/6/2026
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaCrítica (9.8)6.3%—Net-snmpDebian Linux7/3/201817/6/2026
NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
ModificadaAlta (8.8)1.1%—Castlerock Snmpc10/4/201717/6/2026
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
ModificadaMedia (6.1)0.78%—Castlerock Snmpc10/4/201717/6/2026
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
ModificadaMedia (6.5)9.9%💥 ExploitGE Snmp/web Adapter Firmware5/2/201617/6/2026
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.
ModificadaAlta (8.8)14%💥 ExploitGE UPS Snmp WEB Adapter Firmware5/2/201617/6/2026
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.
ModificadaBaja (2.1)0.54%—Net-snmp10/11/201517/6/2026
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.
ModificadaAlta (7.5)41%💥 ExploitNet-snmp19/8/201517/6/2026
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Orbitaley — Vulnerabilidades