Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.70% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 18/10/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.7.39 and prior and 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (4.3) | 0.98% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 18/10/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.39 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Alta (7.1) | 1.3% | 💥 PoC | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 17/10/2022 | 17/6/2026 | A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated… | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+3 | 17/10/2022 | 17/6/2026 | A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this… | |
| Modificada | Alta (7.8) | 0.27% | — | GrafanaNetapp E-series Performance Analyzer | 13/10/2022 | 17/6/2026 | Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions… | |
| Modificada | Crítica (9.8) | 100% | 💥 Exploit | Apache Commons TextNetapp BluexpJuniper Security Threat Response Manager | 13/10/2022 | 17/6/2026 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with… | |
| Modificada | Alta (7.5) | 3.4% | — | Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation | 2/10/2022 | 7/10/2026 | In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. | |
| Modificada | Alta (7.5) | 3.4% | — | Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation | 2/10/2022 | 7/10/2026 | In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. | |
| Modificada | Alta (7.5) | 0.73% | — | Netapp Snapcenter | 29/9/2022 | 17/6/2026 | SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that otherwise would be prevented. | |
| Modificada | Baja (3.7) | 2.4% | — | Haxx CurlNetapp Clustered Data OntapNetapp Element SoftwareNetapp HCI Management Node+9 | 23/9/2022 | 17/6/2026 | When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings. | |
| Modificada | Alta (7.5) | 3.0% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager | 21/9/2022 | 1/9/2026 | By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. | |
| Modificada | Alta (7.5) | 3.2% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager | 21/9/2022 | 1/9/2026 | By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. | |
| Modificada | Alta (7) | 0.47% | — | Linux KernelDebian LinuxNetapp HCI Baseboard Management ControllerCanonical Ubuntu Linux | 21/9/2022 | 17/6/2026 | mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move. | |
| Modificada | Alta (7.1) | 0.26% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 14/9/2022 | 17/6/2026 | A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information. | |
| Modificada | Alta (7.8) | 0.31% | — | Linux KernelRedhat Enterprise LinuxNetapp H300s FirmwareNetapp H500s Firmware+3 | 9/9/2022 | 17/6/2026 | A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes. | |
| Modificada | Crítica (9.8) | 1.3% | — | Systemd Project SystemdNetapp Active IQ Unified ManagerNetapp H300s FirmwareNetapp H500s Firmware+2 | 9/9/2022 | 17/6/2026 | A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object,… | |
| Modificada | Alta (7.8) | 0.34% | — | Linux KernelNetapp HCI Baseboard Management Controller | 2/9/2022 | 17/6/2026 | An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations. | |
| Modificada | Media (4.9) | 0.89% | — | Redhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Single Sign-on+5 | 1/9/2022 | 17/6/2026 | A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. | |
| Modificada | Alta (7) | 0.33% | — | Linux KernelNetapp HCI Baseboard Management Controller | 1/9/2022 | 17/6/2026 | A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc. | |
| Modificada | Alta (8.1) | 1.9% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571. | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591. | |
| Modificada | Media (5.5) | 0.21% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345. | |
| Modificada | Media (5.5) | 0.18% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554. | |
| Modificada | Media (6.5) | 0.49% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465. | |
| Modificada | Media (6.5) | 0.41% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825. |