Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)17%—NTPNetapp Oncommand BalanceNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+27/8/201717/6/2026
Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.
ModificadaCrítica (9.8)12%—NTPNetapp Oncommand Performance ManagerNetapp Oncommand Unified ManagerNetapp Clustered Data Ontap+47/8/201717/6/2026
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
ModificadaAlta (7.5)11%—NTPDebian LinuxNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+107/8/201717/6/2026
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
ModificadaMedia (6.5)5.2%—NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+97/8/201717/6/2026
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
ModificadaAlta (7.5)6.5%—NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+97/8/201717/6/2026
Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).
ModificadaAlta (7.5)6.5%—NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+97/8/201717/6/2026
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
ModificadaAlta (7.5)7.1%—NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+97/8/201717/6/2026
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
ModificadaAlta (7.5)13%—Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerDebian Linux+727/7/201717/6/2026
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers,…
ModificadaAlta (7.5)3.8%—NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+924/7/201717/6/2026
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to…
ModificadaMedia (6.5)1.3%—Netapp Clustered Data Ontap17/7/201717/6/2026
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
ModificadaCrítica (9.1)4.7%—PHPNetapp Clustered Data Ontap10/7/201717/6/2026
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.
ModificadaAlta (7.5)0.84%—Netapp Clustered Data Ontap3/7/201717/6/2026
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
ModificadaAlta (7.5)57%—Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+920/6/201717/6/2026
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force…
ModificadaCrítica (9.8)20%—Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+1020/6/201717/6/2026
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
ModificadaCrítica (9.8)7.5%—ZlibOpensuse LeapOpensuseDebian Linux+3523/5/201714/7/2026
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
ModificadaCrítica (9.8)3.6%—PHPNetapp Clustered Data OntapNetapp Storage Automation Store21/5/201717/6/2026
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
ModificadaAlta (8.4)0.45%—Oracle Supercluster Specific Software24/4/201717/6/2026
Vulnerability in the Oracle SuperCluster Specific Software component of Oracle Sun Systems Products Suite (subcomponent: Backup/Restore Utility). Supported versions that are affected are 2.3.8 and 2.3.13. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle…
ModificadaMedia (5.4)1.4%—Oracle Mysql Cluster24/4/201717/6/2026
Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: DD). Supported versions that are affected are 7.2.27 and earlier, 7.3.16 and earlier, 7.4.14 and earlier and 7.5.5 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple…
ModificadaBaja (2.8)0.37%—Oracle Solaris Cluster24/4/201717/6/2026
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4.3. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris Cluster executes to compromise…
ModificadaAlta (8.1)2.3%—Clusterlabs PCSFedoraproject FedoraRedhat Enterprise Linux21/4/201717/6/2026
Session fixation vulnerability in pcsd in pcs before 0.9.157.
ModificadaAlta (8.8)1.4%—Clusterlabs PCSFedoraproject FedoraRedhat Enterprise Linux21/4/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
ModificadaAlta (7.5)2.7%—Redhat MOD ClusterRedhat Enterprise Linux12/4/201717/6/2026
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
ModificadaMedia (5.3)1.7%—Netapp Clustered Data Ontap10/4/201717/6/2026
NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors.
ModificadaAlta (7.5)1.7%—Netapp Clustered Data Ontap10/4/201717/6/2026
NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors.
ModificadaAlta (7.5)3.3%—Clusterlabs PacemakerOpensuse LeapOpensuse Project LeapSuse Linux Enterprise High Availability+324/3/201717/6/2026
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
Orbitaley — Vulnerabilidades