Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.47% | — | Spring-boot-admin Project Spring-boot-admin | 26/8/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (4.8) | 0.53% | — | Pbootcms | 12/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. | |
| Modificada | Media (5.5) | 0.36% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+1 | 8/8/2021 | 17/6/2026 | btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info. | |
| Modificada | Alta (7.5) | 3.2% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+1 | 8/8/2021 | 17/6/2026 | fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. | |
| Modificada | Alta (7.5) | 3.4% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+1 | 8/8/2021 | 17/6/2026 | net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations. | |
| Modificada | Media (6.5) | 1.2% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+2 | 8/8/2021 | 17/6/2026 | fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection. | |
| Analizada | Alta (7.8) | 0.40% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+3 | 7/8/2021 | 17/6/2026 | In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation… | |
| Modificada | Crítica (9.8) | 2.3% | — | Jeecg Boot | 6/8/2021 | 17/6/2026 | An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.6% | — | Jeecg Boot | 6/8/2021 | 17/6/2026 | A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information. | |
| Modificada | Media (6.5) | 0.80% | — | Pbootcms | 9/7/2021 | 17/6/2026 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. | |
| Modificada | Crítica (9.8) | 2.5% | — | Pbootcms | 8/7/2021 | 17/6/2026 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. | |
| Modificada | Media (4.8) | 0.57% | — | Pbootcms | 8/7/2021 | 9/7/2026 | Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php. | |
| Analizada | Baja (3.3) | 0.60% | — | Debian LinuxNetapp Active IQ Unified ManagerNetapp Bootstrap OSNetapp H610c Firmware+4 | 1/7/2021 | 17/6/2026 | The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list). | |
| Modificada | Media (6.1) | 1.3% | — | React-bootstrap-table Project React-bootstrap-table | 24/6/2021 | 17/6/2026 | All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output. | |
| Modificada | Media (4.8) | 0.48% | — | Pbootcms | 3/6/2021 | 17/6/2026 | Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. | |
| Modificada | Alta (8.8) | 0.95% | — | Atlassian Connect Spring Boot | 10/5/2021 | 17/6/2026 | Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs… | |
| Modificada | Media (6.5) | 0.65% | — | Atlassian Connect Spring Boot | 16/4/2021 | 17/6/2026 | Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs with a server-to-server JWT… | |
| Modificada | Alta (7.5) | 1.1% | — | Pbootcms | 31/3/2021 | 17/6/2026 | PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account. | |
| Modificada | Crítica (9.8) | 2.4% | — | Vmware Spring BootNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCINetapp Solidfire & HCI Management Node | 15/3/2021 | 17/6/2026 | Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56… | |
| Modificada | Alta (7.8) | 1.1% | — | Denx U-boot | 17/2/2021 | 17/6/2026 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT. | |
| Modificada | Alta (7.8) | 1.1% | — | Denx U-boot | 17/2/2021 | 17/6/2026 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. | |
| Modificada | Alta (7.7) | 21% | 💥 Exploit | Spring-boot-actuator-logview Project Spring-boot-actuator-logview | 5/1/2021 | 17/6/2026 | spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log… | |
| Modificada | Alta (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 14/12/2020 | 17/6/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modificada | Baja (3.7) | 3.9% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. |