Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
163 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.69% | 💥 PoC | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+7 | 10/5/2021 | 17/6/2026 | net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller. | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller FirmwareNetapp H300s Firmware+7 | 6/5/2021 | 17/6/2026 | An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The… | |
| Modificada | Alta (7.1) | 0.38% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+15 | 6/5/2021 | 5/8/2026 | A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability. | |
| Analizada | Alta (7) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+11 | 22/4/2021 | 30/7/2026 | A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list… | |
| Analizada | Alta (7.1) | 0.37% | — | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+8 | 19/4/2021 | 1/9/2026 | An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from… | |
| Modificada | Media (6.7) | 0.80% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Fas/aff Baseboard Management Controller+1 | 22/3/2021 | 17/6/2026 | In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and… | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+3 | 22/3/2021 | 17/6/2026 | In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6. | |
| Modificada | Media (4.7) | 0.27% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+3 | 22/3/2021 | 17/6/2026 | A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc. | |
| Modificada | Alta (7.8) | 0.38% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp A250 Firmware+3 | 20/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.) | |
| Modificada | Media (5.5) | 0.28% | — | Linux KernelFedoraproject FedoraNetapp A250 FirmwareNetapp AFF 500f Firmware+3 | 20/3/2021 | 17/6/2026 | An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, aka CID-3ebba796fa25. | |
| Modificada | Alta (8.8) | 1.3% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+8 | 17/3/2021 | 17/6/2026 | rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have… | |
| Modificada | Alta (7.8) | 0.30% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware | 15/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308. | |
| Analizada | Alta (7.8) | 2.1% | 💥 PoC | Netapp Cloud BackupLinux KernelDebian LinuxOracle Tekelec Platform Distribution+1 | 7/3/2021 | 30/7/2026 | An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink… | |
| Analizada | Alta (7.1) | 0.97% | — | Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+2 | 7/3/2021 | 30/7/2026 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. | |
| Modificada | Media (4.4) | 0.71% | — | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware | 7/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at… | |
| Modificada | Media (6.5) | 0.42% | — | Linux KernelXENNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware | 5/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has… | |
| Modificada | Media (6.5) | 0.71% | — | Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware | 5/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a… | |
| Modificada | Alta (7.8) | 0.84% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function. | |
| Modificada | Alta (7.8) | 0.38% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function. | |
| Modificada | Alta (7.8) | 0.42% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function. | |
| Modificada | Alta (7.8) | 0.42% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function. | |
| Modificada | Alta (7.8) | 0.33% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function. | |
| Modificada | Alta (7.8) | 0.73% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function. | |
| Modificada | Alta (7.8) | 0.33% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function. | |
| Modificada | Alta (7.8) | 0.33% | — | HPE Baseboard Management Controller | 8/2/2021 | 17/6/2026 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function. |