Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 11% | — | Debian LinuxISC BindFedoraproject FedoraNetapp Active IQ Unified Manager+12 | 29/4/2021 | 17/6/2026 | In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw… | |
| Modificada | Media (6.5) | 6.0% | — | ISC BindDebian LinuxFedoraproject FedoraSiemens Sinec Infrastructure Network Services+11 | 29/4/2021 | 17/6/2026 | In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR… | |
| Modificada | Alta (7.8) | 0.21% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 26/4/2021 | 17/6/2026 | IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811. | |
| Analizada | Alta (7) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+11 | 22/4/2021 | 30/7/2026 | A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list… | |
| Analizada | Alta (7.1) | 0.37% | — | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+8 | 19/4/2021 | 1/9/2026 | An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from… | |
| Modificada | Alta (7.8) | 0.93% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+9 | 8/4/2021 | 17/6/2026 | BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c. | |
| Modificada | Alta (8.1) | 3.2% | 💥 Exploit | Database-backups Project Database-backups | 5/4/2021 | 17/6/2026 | The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups. | |
| Modificada | Media (6.1) | 0.38% | — | VM Backups Project VM Backups | 5/4/2021 | 17/6/2026 | The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue. | |
| Modificada | Media (4.3) | 0.41% | — | VM Backups Project VM Backups | 5/4/2021 | 17/6/2026 | The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current . | |
| Modificada | Alta (7.2) | 84% | 💥 Exploit | Backup-guard Backup Guard | 5/4/2021 | 17/6/2026 | The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE. | |
| Modificada | Media (5.5) | 1.3% | — | GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility | 26/3/2021 | 17/6/2026 | A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (6.3) | 0.30% | — | GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+2 | 26/3/2021 | 17/6/2026 | There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities… | |
| Modificada | Alta (7.4) | 18% | 💥 PoC | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Media (6.7) | 0.80% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Fas/aff Baseboard Management Controller+1 | 22/3/2021 | 17/6/2026 | In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and… | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+3 | 22/3/2021 | 17/6/2026 | In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6. | |
| Modificada | Media (4.7) | 0.27% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+3 | 22/3/2021 | 17/6/2026 | A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc. | |
| Modificada | Alta (7.8) | 0.38% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp A250 Firmware+3 | 20/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.) | |
| Modificada | Media (5.5) | 0.28% | — | Linux KernelFedoraproject FedoraNetapp A250 FirmwareNetapp AFF 500f Firmware+3 | 20/3/2021 | 17/6/2026 | An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, aka CID-3ebba796fa25. | |
| Modificada | Alta (8.8) | 1.3% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+8 | 17/3/2021 | 17/6/2026 | rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have… | |
| Modificada | Alta (7.8) | 0.30% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware | 15/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308. | |
| Analizada | Alta (7.8) | 2.1% | 💥 PoC | Netapp Cloud BackupLinux KernelDebian LinuxOracle Tekelec Platform Distribution+1 | 7/3/2021 | 30/7/2026 | An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink… | |
| Analizada | Alta (7.1) | 0.97% | — | Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+2 | 7/3/2021 | 30/7/2026 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. | |
| Modificada | Media (4.4) | 0.71% | — | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware | 7/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at… | |
| Modificada | Alta (7.1) | 3.4% | — | Openbsd OpensshFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+5 | 5/3/2021 | 17/6/2026 | ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host. |