Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

1343 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.7)6.3%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+295/8/202117/6/2026
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing…
ModificadaMedia (5.3)1.9%—Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+125/8/202117/6/2026
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's…
ModificadaMedia (6.5)4.3%—Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+125/8/202117/6/2026
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then…
ModificadaCrítica (9.1)2.6%—GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+322/7/202117/6/2026
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have…
ModificadaMedia (5.5)8.8%—Systemd Project SystemdFedoraproject FedoraDebian LinuxNetapp HCI Management Node+120/7/202117/6/2026
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
ModificadaAlta (7.8)9.7%—Linux KernelFedoraproject FedoraDebian LinuxNetapp HCI Management Node+320/7/202117/6/2026
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
ModificadaMedia (5.3)99%—Eclipse JettyNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB ServicesNetapp Element Plug-in FOR Vcenter Server+1415/7/202117/6/2026
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
ModificadaAlta (7.8)7.4%—Nodejs Node.jsSiemens Sinec Infrastructure Network Services12/7/202117/6/2026
Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.
ModificadaMedia (5.3)23%—Nodejs Node.jsSiemens Sinec Infrastructure Network Services12/7/202117/6/2026
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures…
AnalizadaAlta (7.8)79%⚠ Explotación activaNetapp C400 FirmwareNetapp C250 FirmwareNetapp H410c FirmwareNetapp H300s Firmware+177/7/202117/6/2026
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
ModificadaAlta (8.8)1.4%—Nodemailer29/6/202117/6/2026
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
ModificadaAlta (8.1)60%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+2211/6/202117/6/2026
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at…
ModificadaMedia (5.3)3.0%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+1811/6/202117/6/2026
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if…
ModificadaMedia (6.7)0.30%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+49/6/202117/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.4)0.27%—Intel BiosSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e Firmware+149/6/202117/6/2026
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaBaja (3.3)0.38%—Intel MicrocodeDebian LinuxNetapp Fas/aff BiosNetapp HCI Compute Node Bios+19/6/202117/6/2026
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)0.40%—Intel MicrocodeDebian LinuxNetapp Fas/aff BiosNetapp HCI Compute Node Bios+19/6/202117/6/2026
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.30%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+59/6/202117/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.35%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+79/6/202117/6/2026
Out of bounds read in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.8)0.32%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+49/6/202117/6/2026
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaMedia (4.4)0.30%—Intel BiosSiemens Simatic Ipc547g FirmwareNetapp Cloud BackupNetapp AFF Bios+59/6/202117/6/2026
Out of bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.35%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+159/6/202117/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.50%—Linux KernelNetapp Solidfire Baseboard Management Controller FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+187/6/202117/6/2026
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
ModificadaMedia (5.5)5.4%—GstreamerNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+82/6/202117/6/2026
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
ModificadaAlta (7.8)0.38%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire & HCI Management Node+827/5/202117/6/2026
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off…