Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2520 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.70%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.7.39 and prior and 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.…
ModificadaMedia (4.3)0.98%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.39 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.…
ModificadaAlta (7.1)1.3%💥 PoCLinux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+217/10/202217/6/2026
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated…
ModificadaAlta (7.8)0.43%—Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+317/10/202217/6/2026
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this…
ModificadaAlta (7.8)0.27%—GrafanaNetapp E-series Performance Analyzer13/10/202217/6/2026
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions…
ModificadaCrítica (9.8)100%💥 ExploitApache Commons TextNetapp BluexpJuniper Security Threat Response Manager13/10/202217/6/2026
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with…
ModificadaAlta (7.5)3.4%—Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation2/10/20227/10/2026
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
ModificadaAlta (7.5)3.4%—Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation2/10/20227/10/2026
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
ModificadaAlta (7.5)0.73%—Netapp Snapcenter29/9/202217/6/2026
SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that otherwise would be prevented.
ModificadaBaja (3.7)2.4%—Haxx CurlNetapp Clustered Data OntapNetapp Element SoftwareNetapp HCI Management Node+923/9/202217/6/2026
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
ModificadaAlta (7.5)3.0%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager21/9/20221/9/2026
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
ModificadaAlta (7.5)3.2%—ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager21/9/20221/9/2026
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
ModificadaAlta (7)0.47%—Linux KernelDebian LinuxNetapp HCI Baseboard Management ControllerCanonical Ubuntu Linux21/9/202217/6/2026
mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
ModificadaAlta (7.1)0.26%—Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+214/9/202217/6/2026
A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.
ModificadaAlta (7.8)0.31%—Linux KernelRedhat Enterprise LinuxNetapp H300s FirmwareNetapp H500s Firmware+39/9/202217/6/2026
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
ModificadaCrítica (9.8)1.3%—Systemd Project SystemdNetapp Active IQ Unified ManagerNetapp H300s FirmwareNetapp H500s Firmware+29/9/202217/6/2026
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object,…
ModificadaAlta (7.8)0.34%—Linux KernelNetapp HCI Baseboard Management Controller2/9/202217/6/2026
An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.
ModificadaMedia (4.9)0.89%—Redhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Single Sign-on+51/9/202217/6/2026
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
ModificadaAlta (7)0.33%—Linux KernelNetapp HCI Baseboard Management Controller1/9/202217/6/2026
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.
ModificadaAlta (8.1)1.9%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
ModificadaAlta (7.5)1.7%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.
ModificadaMedia (5.5)0.21%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
ModificadaMedia (5.5)0.18%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.
ModificadaMedia (6.5)0.49%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465.
ModificadaMedia (6.5)0.41%—IBM Cognos AnalyticsNetapp Oncommand Insight1/9/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.