Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
155 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.1% | — | Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+31 | 26/2/2022 | 17/6/2026 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | |
| Modificada | Media (5.5) | 0.53% | — | Polkit Project PolkitRedhat Enterprise LinuxFedoraproject FedoraCanonical Ubuntu Linux+2 | 21/2/2022 | 17/6/2026 | There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. | |
| Modificada | Alta (7.5) | 4.7% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. | |
| Modificada | Media (6.5) | 3.3% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element. | |
| Modificada | Crítica (9.8) | 34% | 💥 PoC | Libexpat Project LibexpatDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+1 | 16/2/2022 | 17/6/2026 | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 16/2/2022 | 17/6/2026 | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. | |
| Modificada | Alta (7.5) | 8.3% | — | PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+6 | 9/2/2022 | 17/6/2026 | A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a… | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… | |
| Modificada | Media (5.5) | 0.26% | — | Oracle Http ServerOracle ZFS Storage Appliance KITOracle Solaris | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this… | |
| Modificada | Media (5.3) | 2.8% | — | Oracle GraalvmOracle Http ServerOracle JDKOracle JRE+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker… | |
| Modificada | Alta (7.5) | 3.8% | — | WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+1 | 30/12/2021 | 17/6/2026 | Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 3.8% | — | WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+1 | 30/12/2021 | 17/6/2026 | Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Modificada | Media (5.5) | 1.5% | — | WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT | 30/12/2021 | 17/6/2026 | Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file | |
| Modificada | Alta (7.5) | 3.2% | — | WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT | 30/12/2021 | 17/6/2026 | Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 3.8% | — | WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+1 | 30/12/2021 | 17/6/2026 | Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Analizada | Crítica (9.8) | 97% | 💥 Exploit | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+10 | 20/12/2021 | 17/6/2026 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. | |
| Modificada | Alta (7.1) | 2.7% | — | LxmlFedoraproject FedoraDebian LinuxNetapp Solidfire+7 | 13/12/2021 | 17/6/2026 | lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade… | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Owasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+2 | 7/12/2021 | 17/6/2026 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for… | |
| Modificada | Media (5.3) | 11% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp H300s Firmware+11 | 27/10/2021 | 17/6/2026 | In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause… | |
| Modificada | Alta (7) | 2.5% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+8 | 26/9/2021 | 14/7/2026 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Crítica (9.8) | 39% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+7 | 16/9/2021 | 17/6/2026 | ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Alta (7.5) | 63% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+9 | 16/9/2021 | 17/6/2026 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). | |
| Modificada | Alta (7.5) | 65% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+14 | 16/9/2021 | 17/6/2026 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. |