Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

163 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.69%💥 PoCLinux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+710/5/202117/6/2026
net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
ModificadaAlta (7.8)0.41%—Linux KernelNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller FirmwareNetapp H300s Firmware+76/5/202117/6/2026
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The…
ModificadaAlta (7.1)0.38%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+156/5/20215/8/2026
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
AnalizadaAlta (7)0.47%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1122/4/202130/7/2026
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list…
AnalizadaAlta (7.1)0.37%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+819/4/20211/9/2026
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from…
ModificadaMedia (6.7)0.80%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Fas/aff Baseboard Management Controller+122/3/202117/6/2026
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and…
ModificadaMedia (5.5)0.39%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+322/3/202117/6/2026
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
ModificadaMedia (4.7)0.27%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+322/3/202117/6/2026
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.
ModificadaAlta (7.8)0.38%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp A250 Firmware+320/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)
ModificadaMedia (5.5)0.28%—Linux KernelFedoraproject FedoraNetapp A250 FirmwareNetapp AFF 500f Firmware+320/3/202117/6/2026
An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, aka CID-3ebba796fa25.
ModificadaAlta (8.8)1.3%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+817/3/202117/6/2026
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have…
ModificadaAlta (7.8)0.30%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware15/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
AnalizadaAlta (7.8)2.1%💥 PoCNetapp Cloud BackupLinux KernelDebian LinuxOracle Tekelec Platform Distribution+17/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink…
AnalizadaAlta (7.1)0.97%—Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+27/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
ModificadaMedia (4.4)0.71%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware7/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at…
ModificadaMedia (6.5)0.42%—Linux KernelXENNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware5/3/202117/6/2026
An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has…
ModificadaMedia (6.5)0.71%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware5/3/202117/6/2026
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a…
ModificadaAlta (7.8)0.84%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.
ModificadaAlta (7.8)0.38%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.
ModificadaAlta (7.8)0.42%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function.
ModificadaAlta (7.8)0.42%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.
ModificadaAlta (7.8)0.33%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.
ModificadaAlta (7.8)0.73%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.
ModificadaAlta (7.8)0.33%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.
ModificadaAlta (7.8)0.33%—HPE Baseboard Management Controller8/2/202117/6/2026
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.
Orbitaley — Vulnerabilidades