Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 53% | — | Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 7/11/2022 | 17/6/2026 | handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Media (6.5) | 52% | — | Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 7/11/2022 | 17/6/2026 | handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Alta (7.8) | 0.38% | — | Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp HCI Management Node+2 | 20/8/2020 | 17/6/2026 | Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root. | |
| Modificada | Alta (7.8) | 0.46% | — | Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp Smi-s Provider+1 | 20/8/2020 | 17/6/2026 | Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. | |
| Modificada | Crítica (9.8) | 2.0% | — | SnmpttDebian Linux | 16/8/2020 | 17/6/2026 | SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec. | |
| Modificada | Media (6.5) | 2.3% | — | Net-snmpOracle ZFS Storage Appliance KIT | 25/6/2020 | 17/6/2026 | net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release. | |
| Modificada | Alta (7.5) | 0.72% | — | Castlerock Snmpc Online | 9/4/2020 | 17/6/2026 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value. | |
| Modificada | Media (5.4) | 0.56% | — | Castlerock Snmpc Online | 9/4/2020 | 17/6/2026 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities. | |
| Modificada | Alta (7.5) | 1.4% | — | Castlerock Snmpc Online | 9/4/2020 | 17/6/2026 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files. | |
| Modificada | Alta (7.5) | 1.5% | — | Castlerock Snmpc Online | 9/4/2020 | 17/6/2026 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4. | |
| Modificada | Alta (8.8) | 0.51% | — | Castlerock Snmpc Online | 9/4/2020 | 17/6/2026 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF. | |
| Modificada | Alta (7.5) | 2.2% | — | Minisnmpd Project Minisnmpd | 4/2/2020 | 17/6/2026 | A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a denial of service. To trigger this vulnerability, an attacker needs to simply initiate multiple connections to the… | |
| Modificada | Alta (8.2) | 2.6% | — | Minisnmpd Project Minisnmpd | 4/2/2020 | 17/6/2026 | An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which can result in sensitive information disclosure and Denial Of Service. In order to trigger this vulnerability, an attacker… | |
| Modificada | Crítica (9.1) | 2.4% | — | Minisnmpd Project Minisnmpd | 4/2/2020 | 17/6/2026 | An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To trigger this vulnerability, an attacker… | |
| Modificada | Media (6.7) | 0.34% | — | Intel Snmp Subagent Stand-alone | 17/1/2020 | 17/6/2026 | Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Computerlab Maple Computer WBT Snmp Administrator | 17/7/2019 | 17/6/2026 | SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987. | |
| Modificada | Alta (7.5) | 3.6% | — | Net-snmpNetapp Cloud BackupNetapp Hyper Converged InfrastructureNetapp Storagegrid Webscale+3 | 8/10/2018 | 17/6/2026 | snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Media (6.5) | 18% | 💥 Exploit | Net-snmpDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+6 | 8/10/2018 | 17/6/2026 | _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Crítica (9.8) | 6.3% | — | Net-snmpDebian Linux | 7/3/2018 | 17/6/2026 | NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution. | |
| Modificada | Alta (8.8) | 1.1% | — | Castlerock Snmpc | 10/4/2017 | 17/6/2026 | Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter. | |
| Modificada | Media (6.1) | 0.78% | — | Castlerock Snmpc | 10/4/2017 | 17/6/2026 | Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP. | |
| Modificada | Media (6.5) | 9.9% | 💥 Exploit | GE Snmp/web Adapter Firmware | 5/2/2016 | 17/6/2026 | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors. | |
| Modificada | Alta (8.8) | 14% | 💥 Exploit | GE UPS Snmp WEB Adapter Firmware | 5/2/2016 | 17/6/2026 | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.54% | — | Net-snmp | 10/11/2015 | 17/6/2026 | The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file. | |
| Modificada | Alta (7.5) | 41% | 💥 Exploit | Net-snmp | 19/8/2015 | 17/6/2026 | The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet. |