Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 8.6% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageOracle Agile Product Lifecycle Management+8 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). | |
| Analizada | Alta (8.1) | 8.1% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+9 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). | |
| Modificada | Alta (8.1) | 4.5% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+11 | 14/6/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and… | |
| Modificada | Media (4.4) | 0.62% | — | Linux KernelOpensuse LeapCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+15 | 12/6/2020 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. | |
| Modificada | Alta (7.8) | 0.99% | 💥 PoC | Linux KernelOpensuse LeapRedhat Enterprise LinuxRedhat Enterprise MRG+6 | 9/6/2020 | 17/6/2026 | A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system. | |
| Modificada | Alta (7.7) | 4.1% | — | Postgresql Jdbc DriverQuarkusNetapp Steelstore Cloud Integrated StorageFedoraproject Fedora+1 | 4/6/2020 | 17/6/2026 | PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. | |
| Modificada | Alta (7.4) | 3.3% | — | NTPNetapp Cloud BackupNetapp Clustered Data OntapNetapp Data Ontap+21 | 4/6/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query… | |
| Modificada | Media (6.1) | 2.9% | — | Djangoproject DjangoFedoraproject FedoraCanonical Ubuntu LinuxNetapp SRA Plugin+3 | 3/6/2020 | 17/6/2026 | An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack. | |
| Modificada | Media (5.9) | 6.1% | 💥 PoC | Djangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraNetapp SRA Plugin+3 | 3/6/2020 | 17/6/2026 | An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage. | |
| Modificada | Media (6.5) | 5.2% | — | Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+20 | 18/5/2020 | 17/6/2026 | gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4. | |
| Modificada | Media (5.3) | 0.40% | — | Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+21 | 15/5/2020 | 17/6/2026 | The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+20 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails. | |
| Modificada | Media (6.7) | 0.59% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040. | |
| Modificada | Media (5.5) | 0.65% | — | Linux KernelDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+19 | 9/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8. | |
| Modificada | Media (6.4) | 0.36% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux+18 | 8/5/2020 | 17/6/2026 | There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it… | |
| Modificada | Media (6.7) | 0.71% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud BackupNetapp HCI Baseboard Management Controller+4 | 5/5/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation. | |
| Modificada | Alta (7.8) | 0.45% | — | Linux KernelOpensuse LeapDebian LinuxNetapp Active IQ Unified Manager+18 | 5/5/2020 | 17/6/2026 | An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea. | |
| Modificada | Alta (7) | 0.53% | — | GNU GlibcCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp HCI Management Node+4 | 30/4/2020 | 17/6/2026 | A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that,… | |
| Modificada | Media (6.7) | 0.38% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud BackupNetapp HCI Baseboard Management Controller+5 | 29/4/2020 | 17/6/2026 | An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages. | |
| Modificada | Media (6.7) | 0.80% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud BackupNetapp HCI Baseboard Management Controller+6 | 29/4/2020 | 17/6/2026 | usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. | |
| Modificada | Alta (7) | 0.40% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+19 | 29/4/2020 | 17/6/2026 | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur. | |
| Modificada | Alta (7.5) | 4.4% | — | OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+14 | 28/4/2020 | 17/6/2026 | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). | |
| Modificada | Alta (7.5) | 53% | 💥 PoC | OpensslDebian LinuxFreebsdFedoraproject Fedora+22 | 21/4/2020 | 17/6/2026 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from… | |
| Modificada | Media (5.3) | 4.9% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+15 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in… |