Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.41% | — | IBM Cognos AnalyticsNetapp Oncommand Insight | 1/9/2022 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609. | |
| Modificada | Crítica (9.8) | 1.2% | — | SqliteNetapp Ontap Select Deploy Administration Utility | 1/9/2022 | 17/6/2026 | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause. | |
| Modificada | Media (6.1) | 0.56% | — | LibtiffFedoraproject FedoraRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility+1 | 31/8/2022 | 17/6/2026 | A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service. | |
| Modificada | Media (5.5) | 0.56% | — | LibtiffFedoraproject FedoraRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility+1 | 31/8/2022 | 17/6/2026 | A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Openshift Application RuntimesRedhat Single Sign-onRedhat UndertowNetapp Active IQ Unified Manager+3 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet… | |
| Modificada | Alta (7.5) | 1.3% | — | Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+6 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629. | |
| Modificada | Media (5.3) | 1.8% | — | GNU GlibcNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+3 | 31/8/2022 | 17/6/2026 | An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap. | |
| Modificada | Media (6.1) | 1.5% | — | JsoupNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCINetapp Oncommand Workflow Automation | 29/8/2022 | 17/6/2026 | jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks`… | |
| Modificada | Alta (7) | 0.32% | — | Linux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+3 | 29/8/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Media (5.5) | 0.57% | — | LibtiffNetapp Ontap Select Deploy Administration UtilityDebian Linux | 29/8/2022 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8. | |
| Analizada | Alta (7.5) | 2.0% | — | Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+4 | 29/8/2022 | 11/9/2026 | A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat UndertowNetapp Cloud Secure Agent+2 | 26/8/2022 | 17/6/2026 | A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks. | |
| Modificada | Media (5.3) | 0.60% | — | Netapp Active IQ Unified Manager | 25/8/2022 | 17/6/2026 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a vulnerability which could allow an attacker to discover cluster, node and Active IQ Unified Manager specific information via AutoSupport telemetry data that is sent even when AutoSupport has been… | |
| Modificada | Media (5.5) | 0.52% | — | LibpngDebian LinuxNetapp Ontap Select Deploy Administration Utility | 24/8/2022 | 17/6/2026 | A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service. | |
| Modificada | Media (6.5) | 1.7% | — | GnutlsRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+1 | 24/8/2022 | 17/6/2026 | A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances. | |
| Modificada | Alta (7.1) | 1.2% | 💥 PoC | Linux KernelDebian LinuxRedhat Enterprise LinuxNetapp H300s Firmware+4 | 24/8/2022 | 17/6/2026 | An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information. | |
| Modificada | Media (5.3) | 3.2% | — | PythonDebian LinuxRedhat Software CollectionsRedhat Enterprise Linux+1 | 24/8/2022 | 17/6/2026 | A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given… | |
| Modificada | Alta (7.8) | 0.75% | — | GNU GlibcDebian LinuxNetapp E-series Performance AnalyzerNetapp NFS Plug-in+6 | 24/8/2022 | 17/6/2026 | A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and… | |
| Modificada | Alta (7.5) | 1.8% | — | GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp H300s FirmwareNetapp H500s Firmware+3 | 24/8/2022 | 17/6/2026 | A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data. | |
| Modificada | Alta (7.8) | 0.54% | — | Vmware ToolsDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 23/8/2022 | 17/6/2026 | VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine. | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s Firmware+4 | 23/8/2022 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects. | |
| Modificada | Media (6.5) | 1.5% | 💥 PoC | Redhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+10 | 23/8/2022 | 17/6/2026 | A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged… | |
| Modificada | Media (5.5) | 0.56% | — | Gnome GlibDebian LinuxNetapp Active IQ Unified Manager | 23/8/2022 | 17/6/2026 | A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition. | |
| Modificada | Media (6.1) | 1.7% | — | Apache ArtemisNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 23/8/2022 | 17/6/2026 | In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue. | |
| Modificada | Media (5.5) | 0.31% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s Firmware+5 | 22/8/2022 | 17/6/2026 | An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system. |