Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

841 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—Cisco Ic3000 Industrial Compute GatewayCisco IOXCisco IOS XECisco Cgr1240 Firmware+512/2/202317/6/2026
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An…
AnalizadaAlta (7.8)0.57%—Apple MacosNetapp HCI Compute NodeNeovimVIM+14/1/202324/9/2026
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
ModificadaAlta (7.8)0.18%—Intel NUC 11 Compute Element Cm11ebi38w FirmwareIntel NUC 11 Compute Element Cm11ebc4w FirmwareIntel NUC 11 Compute Element Cm11ebi58w FirmwareIntel NUC 11 Compute Element Cm11ebv58w Firmware+411/11/202217/6/2026
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.19%—Intel NUC 8 Compute Element Cm8i7cb FirmwareIntel NUC 8 Compute Element Cm8i3cb FirmwareIntel NUC 8 Compute Element Cm8ccb FirmwareIntel NUC 8 Compute Element Cm8i5cb Firmware+111/11/202217/6/2026
Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)2.5%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraNetapp H300s Firmware+824/10/202217/6/2026
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
ModificadaAlta (7.5)0.92%—Fastly Js-compute20/9/202217/6/2026
The JS Compute Runtime for Fastly's Compute@Edge platform provides the environment JavaScript is executed in when using the Compute@Edge JavaScript SDK. In versions prior to 0.5.3, the `Math.random` and `crypto.getRandomValues` methods fail to use sufficiently random values. The initial value to seed the PRNG…
ModificadaCrítica (9.8)19%💥 PoCZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+145/8/202214/7/2026
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the…
AnalizadaCrítica (9.8)49%💥 ExploitCvat Computer Vision Annotation Tool1/8/202217/6/2026
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no…
ModificadaAlta (7.5)7.6%💥 PoCLinux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+327/7/202217/6/2026
nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.
ModificadaMedia (5.3)2.5%—Oracle GraalvmOracle JDKOracle JREAzul Zulu+1019/7/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network…
ModificadaMedia (5.9)2.9%—Oracle GraalvmOracle JDKOracle JREOracle Openjdk+1119/7/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability…
ModificadaMedia (5.3)4.2%—Oracle GraalvmOracle JDKOracle JREOracle Openjdk+1119/7/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability…
ModificadaAlta (7.5)82%💥 PoCApache Xalan-javaDebian LinuxOracle GraalvmOracle JDK+1219/7/202217/6/2026
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java…
ModificadaAlta (7.5)2.6%—Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+47/7/202217/6/2026
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good…
ModificadaBaja (2.7)1.3%—Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+37/7/202217/6/2026
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
ModificadaCrítica (9.8)1.5%—HPE Slingshot FirmwareHPE Cray EX Supercomputers FirmwareHPE Cray SH Supercomputer AIR Cooled Base System Code FirmwareHPE Cray SH Supercomputer Liquid Cooled Base System Code Firmware+124/6/202217/6/2026
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX…
ModificadaAlta (7.5)2.7%—Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+82/6/202217/6/2026
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
ModificadaMedia (5.3)2.7%—Haxx CurlNetapp HCI Bootstrap OSNetapp Clustered Data OntapNetapp Solidfire, Enterprise SDS & HCI Storage Node+72/6/202217/6/2026
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided, a more…
ModificadaAlta (8.1)3.8%—Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Oncommand Insight+102/6/202217/6/2026
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
ModificadaMedia (6.7)0.24%—Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+5512/5/202217/6/2026
Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.24%—Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+5512/5/202217/6/2026
Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.24%—Intel Lapbc510 FirmwareIntel Lapbc710 FirmwareIntel Lapkc71f FirmwareIntel Lapkc71e Firmware+5512/5/202217/6/2026
Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.80%💥 PoCLinux KernelDebian LinuxNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+912/5/202217/6/2026
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
ModificadaCrítica (9.8)17%💥 PoCRedplanetcomputers Laundry Management System29/4/202217/6/2026
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
ModificadaAlta (7.5)77%💥 PoCOracle GraalvmOracle JDKDebian LinuxNetapp 7-mode Transition Tool+1219/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with…
Orbitaley — Vulnerabilidades