Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

699 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.47%—Spring-boot-admin Project Spring-boot-admin26/8/202117/6/2026
A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (4.8)0.53%—Pbootcms12/8/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
ModificadaMedia (5.5)0.36%—Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+18/8/202117/6/2026
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
ModificadaAlta (7.5)3.2%—Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+18/8/202117/6/2026
fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd.
ModificadaAlta (7.5)3.4%—Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+18/8/202117/6/2026
net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.
ModificadaMedia (6.5)1.2%—Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+28/8/202117/6/2026
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
AnalizadaAlta (7.8)0.40%—Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+37/8/202117/6/2026
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation…
ModificadaCrítica (9.8)2.3%—Jeecg Boot6/8/202117/6/2026
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
ModificadaAlta (7.5)1.6%—Jeecg Boot6/8/202117/6/2026
A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.
ModificadaMedia (6.5)0.80%—Pbootcms9/7/202117/6/2026
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
ModificadaCrítica (9.8)2.5%—Pbootcms8/7/202117/6/2026
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
ModificadaMedia (4.8)0.57%—Pbootcms8/7/20219/7/2026
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
AnalizadaBaja (3.3)0.60%—Debian LinuxNetapp Active IQ Unified ManagerNetapp Bootstrap OSNetapp H610c Firmware+41/7/202117/6/2026
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
ModificadaMedia (6.1)1.3%—React-bootstrap-table Project React-bootstrap-table24/6/202117/6/2026
All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.
ModificadaMedia (4.8)0.48%—Pbootcms3/6/202117/6/2026
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
ModificadaAlta (8.8)0.95%—Atlassian Connect Spring Boot10/5/202117/6/2026
Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs…
ModificadaMedia (6.5)0.65%—Atlassian Connect Spring Boot16/4/202117/6/2026
Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs with a server-to-server JWT…
ModificadaAlta (7.5)1.1%—Pbootcms31/3/202117/6/2026
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
ModificadaCrítica (9.8)2.4%—Vmware Spring BootNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCINetapp Solidfire & HCI Management Node15/3/202117/6/2026
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56…
ModificadaAlta (7.8)1.1%—Denx U-boot17/2/202117/6/2026
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
ModificadaAlta (7.8)1.1%—Denx U-boot17/2/202117/6/2026
The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
ModificadaAlta (7.7)21%💥 ExploitSpring-boot-actuator-logview Project Spring-boot-actuator-logview5/1/202117/6/2026
spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log…
ModificadaAlta (7.5)4.6%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1314/12/202017/6/2026
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
ModificadaAlta (7.5)9.8%—Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+1814/12/202017/6/2026
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
ModificadaBaja (3.7)3.9%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1814/12/202017/6/2026
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
Orbitaley — Vulnerabilidades