Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)11%—Debian LinuxISC BindFedoraproject FedoraNetapp Active IQ Unified Manager+1229/4/202117/6/2026
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw…
ModificadaMedia (6.5)6.0%—ISC BindDebian LinuxFedoraproject FedoraSiemens Sinec Infrastructure Network Services+1129/4/202117/6/2026
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR…
ModificadaAlta (7.8)0.21%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments26/4/202117/6/2026
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.
AnalizadaAlta (7)0.47%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1122/4/202130/7/2026
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list…
AnalizadaAlta (7.1)0.37%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+819/4/20211/9/2026
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from…
ModificadaAlta (7.8)0.93%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+98/4/202117/6/2026
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.
ModificadaAlta (8.1)3.2%💥 ExploitDatabase-backups Project Database-backups5/4/202117/6/2026
The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.
ModificadaMedia (6.1)0.38%—VM Backups Project VM Backups5/4/202117/6/2026
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.
ModificadaMedia (4.3)0.41%—VM Backups Project VM Backups5/4/202117/6/2026
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .
ModificadaAlta (7.2)84%💥 ExploitBackup-guard Backup Guard5/4/202117/6/2026
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
ModificadaMedia (5.5)1.3%—GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility26/3/202117/6/2026
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
ModificadaMedia (6.3)0.30%—GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+226/3/202117/6/2026
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities…
ModificadaAlta (7.4)18%💥 PoCOpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+2925/3/202117/6/2026
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict…
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaMedia (6.7)0.80%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Fas/aff Baseboard Management Controller+122/3/202117/6/2026
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and…
ModificadaMedia (5.5)0.39%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+322/3/202117/6/2026
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
ModificadaMedia (4.7)0.27%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+322/3/202117/6/2026
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.
ModificadaAlta (7.8)0.38%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp A250 Firmware+320/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)
ModificadaMedia (5.5)0.28%—Linux KernelFedoraproject FedoraNetapp A250 FirmwareNetapp AFF 500f Firmware+320/3/202117/6/2026
An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, aka CID-3ebba796fa25.
ModificadaAlta (8.8)1.3%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+817/3/202117/6/2026
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have…
ModificadaAlta (7.8)0.30%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware15/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
AnalizadaAlta (7.8)2.1%💥 PoCNetapp Cloud BackupLinux KernelDebian LinuxOracle Tekelec Platform Distribution+17/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink…
AnalizadaAlta (7.1)0.97%—Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+27/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
ModificadaMedia (4.4)0.71%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware7/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at…
ModificadaAlta (7.1)3.4%—Openbsd OpensshFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+55/3/202117/6/2026
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.