Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

699 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.7%—Denx U-bootFedoraproject Fedora16/5/202217/6/2026
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
ModificadaAlta (7.2)1.1%—Springbootmovie Project Springbootmovie3/5/202217/6/2026
In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability
ModificadaMedia (5.4)0.49%—Springbootmovie Project Springbootmovie3/5/202217/6/2026
In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters, resulting in stored XSS.
ModificadaCrítica (9.8)1.9%—Coreboot25/4/202217/6/2026
An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.
ModificadaMedia (5.3)2.8%—Oracle GraalvmOracle Java SENetapp Active IQ Unified ManagerNetapp Cloud Insights Acquisition Unit+1219/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows…
ModificadaAlta (7.5)4.0%—Oracle GraalvmOracle JDKNetapp Active IQ Unified ManagerNetapp Cloud Insights Acquisition Unit+1319/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows…
ModificadaBaja (3.7)2.7%—Oracle GraalvmOracle Java SENetapp Active IQ Unified ManagerNetapp Cloud Insights Acquisition Unit+1219/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows…
ModificadaMedia (6.1)0.79%—Ecommerce Codeigniter Bootstrap Project Ecommerce Codeigniter Bootstrap8/4/202217/6/2026
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.
ModificadaAlta (7.8)0.60%💥 PoCVmware Spring Boot30/3/202217/6/2026
spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer…
ModificadaMedia (6.8)1.7%—Linux KernelNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Element Software+1225/3/202217/6/2026
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.
ModificadaMedia (6.8)0.25%—GE UR Bootloader Binary23/3/202217/6/2026
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
ModificadaMedia (6.1)0.91%—Jeecg Boot10/3/202217/6/2026
A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.
AnalizadaAlta (7.8)5.5%⚠ Explotación activa💥 ExploitNetapp H300s FirmwareNetapp H410c FirmwareNetapp H410s FirmwareNetapp H500s Firmware+233/3/202217/6/2026
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
ModificadaMedia (5.4)0.60%—Bootstrapped Dynamic Widgets28/2/202217/6/2026
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue
ModificadaAlta (7.5)5.1%—Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+3126/2/202217/6/2026
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
ModificadaMedia (5.9)0.67%—Linux KernelNetapp Cloud Volumes Ontap MediatorNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage Node+1326/2/202217/6/2026
An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.
ModificadaCrítica (9.8)1.4%—Jeecg Boot16/2/202217/6/2026
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.
ModificadaCrítica (9.8)1.4%—Jeecg Boot16/2/202217/6/2026
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
ModificadaMedia (4.7)0.36%—Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Element Software+816/2/202217/6/2026
A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.
ModificadaCrítica (9.8)2.0%—Jeecg Boot25/1/202217/6/2026
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
ModificadaMedia (6.1)2.4%—Bootstrap-table Bootstrap Table3/11/202117/6/2026
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
ModificadaCrítica (9.8)1.2%—Openpowerfoundation Skiboot22/10/202117/6/2026
An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uint16_t "year" value, resulting in a type mismatch that can truncate a higher integer value to a smaller one, and bypass a timestamp check. The fix is to use the right endian conversion function.
ModificadaMedia (6.1)0.84%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap1/10/202117/6/2026
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.
ModificadaMedia (5.4)0.64%—Bootstrapped Visual Link Preview20/9/202117/6/2026
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a…
ModificadaAlta (7.8)0.79%—Apple Boot Camp8/9/202117/6/2026
A memory corruption issue was addressed with improved state management. This issue is fixed in Boot Camp 6.1.14. A malicious application may be able to elevate privileges.
Orbitaley — Vulnerabilidades