Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

1345 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.6%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1314/12/202017/6/2026
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
ModificadaAlta (7.5)9.8%—Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+1814/12/202017/6/2026
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
ModificadaBaja (3.7)3.9%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1814/12/202017/6/2026
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
ModificadaMedia (5.6)1.6%—Node-notifier Project Node-notifier11/12/202017/6/2026
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
ModificadaMedia (5.5)1.1%—GNU BinutilsNetapp Cloud BackupNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+19/12/202017/6/2026
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
ModificadaMedia (5.5)1.2%—GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Solidfire & HCI Management Node9/12/202017/6/2026
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file.
ModificadaMedia (5.9)7.1%—OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaMedia (6.5)3.7%—Nodejs Node.js3/12/202017/6/2026
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
ModificadaBaja (3.6)0.41%—Linux KernelDebian LinuxNetapp 500f FirmwareNetapp A250 Firmware+428/11/202017/6/2026
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
ModificadaAlta (7)0.61%—Linux KernelNetapp Cloud BackupNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+328/11/202017/6/2026
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.
ModificadaAlta (7)0.46%—Linux KernelNetapp HCI Management NodeNetapp SolidfireNetapp HCI Compute Node+128/11/202017/6/2026
An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe.
ModificadaAlta (7)0.36%—Linux KernelNetapp Cloud BackupNetapp Element SoftwareNetapp HCI Management Node+328/11/202017/6/2026
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
ModificadaMedia (6.7)0.93%—Linux KernelBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+1523/11/202017/6/2026
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
ModificadaAlta (7.5)54%—Nodejs Node.jsFedoraproject FedoraOracle Blockchain PlatformOracle Graalvm+419/11/202017/6/2026
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
ModificadaMedia (6.7)0.42%—Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.42%—Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Out of bounds write in Intel BIOS platform sample code for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.42%—Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Use of potentially dangerous function in Intel BIOS platform sample code for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.34%—Intel BiosNetapp Cloud BackupNetapp Fas/aff BiosNetapp HCI Compute Node Bios+212/11/202017/6/2026
Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.52%—Intel MicrocodeNetapp Clustered Data OntapNetapp HCI Compute Node BiosNetapp HCI Storage Node Bios+1312/11/202017/6/2026
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.44%—Intel MicrocodeNetapp Clustered Data OntapNetapp HCL Compute Node BiosNetapp HCI Storage Node Bios+312/11/202017/6/2026
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaCrítica (9.8)2.3%—Nodemailer12/11/202017/6/2026
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
ModificadaCrítica (9.8)3.6%—Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+922/10/202017/6/2026
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
AnalizadaMedia (5.3)3.2%—Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+1521/10/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can…
AnalizadaBaja (3.1)2.7%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.7)2.2%—Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+1421/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…