Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 73% | 💥 PoC | OpensslDebian LinuxNetapp Cloud Volumes Ontap MediatorNetapp Clustered Data Ontap+9 | 15/3/2022 | 17/6/2026 | The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded… | |
| Analizada | Crítica (9.8) | 50% | — | Apache Http ServerFedoraproject FedoraDebian LinuxOracle Http Server+1 | 14/3/2022 | 17/6/2026 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. | |
| Modificada | Crítica (9.1) | 42% | — | Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+4 | 14/3/2022 | 17/6/2026 | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. | |
| Modificada | Crítica (9.8) | 28% | 💥 PoC | Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+4 | 14/3/2022 | 17/6/2026 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | |
| Modificada | Alta (7.5) | 69% | — | Apache Http ServerDebian LinuxFedoraproject FedoraOracle Http Server+3 | 14/3/2022 | 17/6/2026 | A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | |
| Modificada | Media (6.5) | 4.7% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+16 | 10/3/2022 | 17/6/2026 | There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to… | |
| Modificada | Media (6) | 0.15% | — | Dell Enterprise Storage Analytics | 4/3/2022 | 17/6/2026 | Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the… | |
| Modificada | Alta (7.5) | 0.93% | — | Netapp Storagegrid | 4/3/2022 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS) of the Local Distribution Router (LDR) service. | |
| Modificada | Media (4.9) | 0.77% | — | Netapp Storagegrid | 4/3/2022 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user accounts to access S3 data to which they previously had access. StorageGRID 11.6.0 obtains the user account status from Active… | |
| Modificada | Alta (7.5) | 3.5% | — | TwistedDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+1 | 3/3/2022 | 17/6/2026 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc… | |
| Analizada | Alta (7.8) | 5.5% | ⚠ Explotación activa💥 Exploit | Netapp H300s FirmwareNetapp H410c FirmwareNetapp H410s FirmwareNetapp H500s Firmware+23 | 3/3/2022 | 17/6/2026 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly. | |
| Modificada | Media (6.5) | 1.2% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxOracle Communications Cloud Native Core Binding Support Function+14 | 2/3/2022 | 17/6/2026 | A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. | |
| Modificada | Alta (7.5) | 5.1% | — | Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+31 | 26/2/2022 | 17/6/2026 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | |
| Modificada | Media (5.9) | 0.67% | — | Linux KernelNetapp Cloud Volumes Ontap MediatorNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage Node+13 | 26/2/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session. | |
| Modificada | Alta (7.5) | 3.1% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process. | |
| Modificada | Crítica (9.8) | 5.2% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution. | |
| Modificada | Crítica (9.8) | 2.7% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions. | |
| Modificada | Media (5.5) | 0.53% | — | Polkit Project PolkitRedhat Enterprise LinuxFedoraproject FedoraCanonical Ubuntu Linux+2 | 21/2/2022 | 17/6/2026 | There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned | |
| Modificada | Media (4.3) | 1.1% | — | SambaRedhat StorageFedoraproject Fedora | 21/2/2022 | 17/6/2026 | All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed. | |
| Modificada | Alta (8.8) | 74% | 💥 PoC | SambaDebian LinuxCanonical Ubuntu LinuxSynology Diskstation Manager+19 | 21/2/2022 | 17/6/2026 | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially… | |
| Analizada | Alta (7.4) | 6.9% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+17 | 18/2/2022 | 30/7/2026 | A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this… | |
| Modificada | Alta (8.1) | 1.6% | — | SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+21 | 18/2/2022 | 17/6/2026 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. | |
| Modificada | Media (5.9) | 1.8% | — | SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+20 | 18/2/2022 | 17/6/2026 | A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. | |
| Modificada | Alta (7.5) | 4.7% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. |