Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

966 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)39%💥 PoCJqueryui Jquery UIFedoraproject FedoraNetapp H500s FirmwareNetapp H700s Firmware+2526/10/202125/8/2026
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS…
ModificadaMedia (6.4)0.84%—Solarwinds Network Performance Monitor21/10/202117/6/2026
Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
ModificadaAlta (7.5)3.6%—RedisFedoraproject FedoraDebian LinuxManagement Services FOR Element Software AND Netapp HCI+14/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnerability involves changing the default proto-max-bulk-len configuration parameter…
ModificadaMedia (6.8)0.15%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the system password.
ModificadaMedia (6.8)0.43%—Bostonscientific Zoom Latitude Programming System Model 3120 FirmwareBostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit these vulnerabilities.
ModificadaMedia (6.8)0.17%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.
ModificadaMedia (6.4)0.23%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate of a valid hardware key. The hardware key allows access to special settings when inserted.
ModificadaAlta (7.6)0.26%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in the world.
ModificadaAlta (8.8)2.6%—RedisDebian LinuxFedoraproject FedoraNetapp Management Services FOR Element Software+24/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a vulnerability in the underlying hiredis library which does not…
ModificadaAlta (7.5)4.1%—RedisFedoraproject FedoraDebian LinuxNetapp Management Services FOR Element Software+24/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or trigger remote code execution. The vulnerability involves changing the default…
ModificadaAlta (7.5)16%💥 PoCRedisFedoraproject FedoraDebian LinuxNetapp Management Services FOR Element Software+24/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements (in the multi-bulk header) and size of each element (in the bulk header). An attacker…
ModificadaMedia (4.3)1.8%—RedisRedhat Software CollectionsRedhat Enterprise LinuxDebian Linux+44/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is…
ModificadaAlta (7.5)14%—RedisFedoraproject FedoraDebian LinuxNetapp Management Services FOR Element Software+24/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves modifying the default ziplist configuration…
ModificadaAlta (7.5)3.9%—RedisFedoraproject FedoraDebian LinuxNetapp Management Services FOR Element Software+24/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves changing the default proto-max-bulk-len and client-query-buffer-limit configuration…
ModificadaAlta (8.8)16%—RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+24/10/202117/6/2026
Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and potentially remote code execution. This…
ModificadaAlta (7.5)2.5%—Openvpn-monitor Project Openvpn-monitor27/9/202117/6/2026
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
ModificadaAlta (7.5)3.3%—Openvpn-monitor Project Openvpn-monitor27/9/202117/6/2026
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
ModificadaMedia (6.5)0.68%—Openvpn-monitor Project Openvpn-monitor27/9/202117/6/2026
furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
AnalizadaAlta (7.8)2.9%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)11%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
AnalizadaAlta (7.8)2.7%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
ModificadaMedia (5.4)0.61%—Paessler Prtg Network Monitor13/9/202117/6/2026
PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.
ModificadaAlta (7.4)50%💥 PoCOpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+2824/8/202117/6/2026
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a…
ModificadaCrítica (9.8)88%—OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+2724/8/202117/6/2026
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the…