Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1280 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)23%—Apache Velocity EngineApache Wss4jDebian LinuxOracle Banking Deposits AND Lines OF Credit Servicing+1210/3/202117/6/2026
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine…
ModificadaAlta (7.8)1.9%—LibtiffDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+19/3/202117/6/2026
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
ModificadaAlta (7.8)1.9%—LibtiffDebian LinuxNetapp Ontap Select Deploy Administration UtilityRedhat Enterprise Linux9/3/202117/6/2026
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
ModificadaMedia (5.5)1.6%—LibtiffNetapp Ontap Select Deploy Administration UtilityFedoraproject FedoraRedhat Enterprise Linux9/3/202117/6/2026
In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.
ModificadaMedia (5.5)1.2%—LibtiffRedhat Enterprise LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility9/3/202117/6/2026
A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.
ModificadaMedia (5.6)3.3%—Facebook React-dev-utils9/3/202117/6/2026
react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this function is manually invoked with…
ModificadaAlta (8.2)0.60%💥 PoCGNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each…
ModificadaMedia (6.7)1.0%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as…
ModificadaAlta (7.5)0.39%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this…
ModificadaMedia (6.7)0.57%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without sufficient bounds checking. If the function is called with a command line that references a variable…
ModificadaAlta (7.6)0.79%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of…
ModificadaAlta (8.2)1.2%💥 PoCGNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections.…
ModificadaAlta (7.5)1.7%💥 PoCGNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+53/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content…
ModificadaMedia (5.5)0.89%—GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp A250 FirmwareNetapp 500f Firmware+1026/2/202117/6/2026
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a…
ModificadaMedia (5.9)2.9%💥 PoCJson-smart Project Json-smart-v1Json-smart Project Json-smart-v2Oracle Communications Cloud Native Core PolicyOracle OSS Support Tools+323/2/202117/6/2026
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
ModificadaMedia (4.4)0.54%—Intel Extreme Tuning Utility17/2/202117/6/2026
Out-of-bounds write in the Intel(R) XTU before version 6.5.3.25 may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (5.9)41%—PythonFedoraproject FedoraDebian LinuxNetapp Cloud Backup+815/2/202117/6/2026
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query…
ModificadaMedia (5.3)1.4%—Qwutils Project Qwutils9/2/202117/6/2026
An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop.
ModificadaAlta (7.5)3.1%—GNU GlibcNetapp E-series Santricity OS ControllerNetapp Ontap Select Deploy Administration UtilityOracle Communications Cloud Native Core Security Edge Protection Proxy+727/1/202117/6/2026
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
AnalizadaAlta (7.8)100%⚠ Explotación activa💥 ExploitSudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+2026/1/202117/6/2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
ModificadaCrítica (9.8)75%💥 PoCOracle CoherenceOracle Utilities Framework20/1/202117/6/2026
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise…
ModificadaCrítica (9.8)23%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+619/1/202117/6/2026
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
ModificadaMedia (5.9)3.6%—GNU GlibcFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp Service Processor+44/1/202117/6/2026
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
Orbitaley — Vulnerabilidades