Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 6.1% | — | ISC DhcpFedoraproject FedoraDebian LinuxSiemens Ruggedcom ROX Rx1400 Firmware+12 | 26/5/2021 | 17/6/2026 | In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those… | |
| Modificada | Alta (7.8) | 0.63% | — | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management Node+9 | 26/5/2021 | 17/6/2026 | A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there is still an alias in sunkbd_reinit causing Use After Free. | |
| Modificada | Alta (7) | 1.0% | — | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management Node+11 | 26/5/2021 | 17/6/2026 | A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op. | |
| Modificada | Alta (8.6) | 17% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+24 | 19/5/2021 | 17/6/2026 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application… | |
| Modificada | Alta (7.8) | 0.65% | — | Linux KernelNetapp Cloud BackupNetapp Solidfire & HCI Management NodeNetapp Solidfire Baseboard Management Controller Firmware+8 | 14/5/2021 | 17/6/2026 | The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue. | |
| Modificada | Media (5.3) | 3.6% | — | Oracle JDKOracle JREDebian LinuxFedoraproject Fedora+7 | 22/4/2021 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to… | |
| Modificada | Media (5.9) | 3.5% | — | Oracle JDKOracle JREDebian LinuxFedoraproject Fedora+8 | 22/4/2021 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to… | |
| Analizada | Alta (7) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+11 | 22/4/2021 | 30/7/2026 | A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list… | |
| Modificada | Crítica (9.8) | 1.3% | — | Psnode Project Psnode | 18/4/2021 | 17/6/2026 | This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | |
| Modificada | Media (5.9) | 1.1% | — | Jose-node-cjs-runtime Project Jose-node-cjs-runtime | 16/4/2021 | 17/6/2026 | jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed`… | |
| Modificada | Media (5.9) | 1.1% | — | Jose-node-cjs-runtime Project Jose-node-cjs-runtime | 16/4/2021 | 17/6/2026 | jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed`… | |
| Modificada | Media (5.9) | 1.1% | — | Jose-node-cjs-runtime Project Jose-node-cjs-runtime | 16/4/2021 | 17/6/2026 | jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed`… | |
| Modificada | Alta (7.8) | 2.0% | — | Microsoft Ms-rest-nodeauth | 13/4/2021 | 17/6/2026 | Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 2.0% | — | Chrono-node Project Chrono-node | 12/4/2021 | 17/6/2026 | This affects the package chrono-node before 2.2.4. It hangs on a date-like string with lots of embedded spaces. | |
| Modificada | Alta (7.8) | 0.93% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+9 | 8/4/2021 | 17/6/2026 | BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c. | |
| Modificada | Media (6.5) | 1.1% | — | Node-etsy-client Project Node-etsy-client | 1/4/2021 | 17/6/2026 | node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-client v0.3.0 and later. | |
| Modificada | Baja (3.7) | 3.1% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+7 | 1/4/2021 | 17/6/2026 | curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server… | |
| Modificada | Media (5.3) | 5.3% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+8 | 1/4/2021 | 17/6/2026 | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP… | |
| Modificada | Media (6.3) | 0.30% | — | GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+2 | 26/3/2021 | 17/6/2026 | There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities… | |
| Modificada | Alta (7.4) | 18% | — | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Media (5.9) | 64% | — | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Crítica (9.8) | 2.4% | — | Vmware Spring BootNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCINetapp Solidfire & HCI Management Node | 15/3/2021 | 17/6/2026 | Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56… | |
| Modificada | Alta (7.1) | 3.4% | — | Openbsd OpensshFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+5 | 5/3/2021 | 17/6/2026 | ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host. | |
| Modificada | Alta (7.5) | 37% | — | Nodejs Node.jsFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+9 | 3/3/2021 | 17/6/2026 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof… | |
| Modificada | Alta (7.5) | 77% | — | Nodejs Node.jsFedoraproject FedoraNetapp E-series Performance AnalyzerOracle Graalvm+5 | 3/3/2021 | 17/6/2026 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new… |