Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2520 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.5)0.46%—GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+106/7/202217/6/2026
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform…
ModificadaCrítica (9.8)45%💥 PoCApache Commons ConfigurationNetapp SnapcenterDebian Linux6/7/202217/6/2026
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation.…
ModificadaMedia (5.3)4.9%💥 PoCOpensslFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap Antivirus Connector+75/7/202217/6/2026
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the…
ModificadaAlta (7.8)5.5%💥 ExploitLinux KernelDebian LinuxCanonical Ubuntu LinuxNetapp H300s Firmware+44/7/202217/6/2026
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user…
ModificadaMedia (6.5)2.8%—GnupgFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+11/7/202217/6/2026
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
ModificadaCrítica (9.8)46%💥 PoCOpensslNetapp SnapcenterNetapp H410c FirmwareNetapp H300s Firmware+31/7/202217/6/2026
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory…
ModificadaMedia (6.5)1.3%—LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraDebian Linux30/6/202217/6/2026
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
ModificadaMedia (6.5)1.3%—LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraDebian Linux30/6/202217/6/2026
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
ModificadaMedia (6.5)1.3%—LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraDebian Linux30/6/202217/6/2026
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
ModificadaMedia (6.1)0.89%—IBM Cognos AnalyticsIBM Planning AnalyticsNetapp Oncommand Insight24/6/202217/6/2026
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…
ModificadaCrítica (9.8)1.7%—IBM Cognos AnalyticsNetapp Oncommand Insight24/6/202217/6/2026
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
ModificadaMedia (6.5)0.98%—IBM Cognos AnalyticsNetapp Oncommand Insight24/6/202217/6/2026
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
ModificadaMedia (5.3)3.0%—Golang GOFedoraproject FedoraNetapp Beegfs CSI Driver23/6/202217/6/2026
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
ModificadaAlta (7.3)95%—OpensslDebian LinuxFedoraproject FedoraSiemens Sinec INS+2421/6/202217/6/2026
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in…
ModificadaAlta (7.5)3.9%—Npmjs NPMNetapp Ontap Select Deploy Administration Utility13/6/202217/6/2026
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files…
AnalizadaCrítica (9.8)3.5%💥 PoCApache Http ServerNetapp Clustered Data OntapFedoraproject Fedora9/6/202217/6/2026
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
AnalizadaAlta (7.5)5.3%—Apache Http ServerNetapp Clustered Data OntapFedoraproject Fedora9/6/202217/6/2026
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
ModificadaAlta (7.5)90%—Apache Http ServerNetapp Clustered Data OntapFedoraproject Fedora9/6/202217/6/2026
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.
ModificadaAlta (7.5)6.4%—Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap9/6/202217/6/2026
In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
ModificadaCrítica (9.1)6.3%—Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap9/6/202217/6/2026
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may…
ModificadaMedia (5.3)5.0%—Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap9/6/202217/6/2026
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the…
AnalizadaAlta (7.5)21%💥 PoCApache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap9/6/202217/6/2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
ModificadaAlta (7.8)0.33%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H410c Firmware+49/6/202217/6/2026
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
ModificadaAlta (7.8)2.9%💥 PoCLinux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+42/6/202217/6/2026
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
ModificadaMedia (4.3)1.3%—Haxx CurlNetapp HCI Bootstrap OSNetapp Clustered Data OntapNetapp Solidfire, Enterprise SDS & HCI Storage Node+62/6/202217/6/2026
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by…