Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
242 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 5.6% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 6.9% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Alta (7.5) | 4.8% | — | Oracle OpenjdkNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage ManagerNetapp E-series Santricity WEB Services+2 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction… | |
| Modificada | Media (5.3) | 16% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 8.5% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+10 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.9) | 7.4% | — | Oracle GraalvmOracle OpenjdkNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+9 | 20/10/2021 | 17/6/2026 | Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (7.4) | 50% | 💥 PoC | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Crítica (9.1) | 2.6% | — | GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+3 | 22/7/2021 | 17/6/2026 | The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have… | |
| Modificada | Media (5.3) | 99% | 💥 Exploit | Eclipse JettyNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB ServicesNetapp Element Plug-in FOR Vcenter Server+14 | 15/7/2021 | 17/6/2026 | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5. | |
| Modificada | Baja (3.5) | 0.96% | 💥 PoC | Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+12 | 22/6/2021 | 17/6/2026 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated.… | |
| Modificada | Alta (7.5) | 1.4% | — | Netapp E-series Santricity OS Controller | 11/6/2021 | 17/6/2026 | E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks. | |
| Modificada | Alta (8.8) | 1.2% | — | Netapp E-series Santricity OS Controller | 11/6/2021 | 17/6/2026 | E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow privileged attackers to execute arbitrary code. | |
| Modificada | Media (5.3) | 1.4% | — | Netapp E-series Santricity OS Controller | 11/6/2021 | 17/6/2026 | E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to cause a partial Denial of Service (DoS) to the web server. | |
| Modificada | Media (6.5) | 1.1% | — | Netapp E-series Santricity OS Controller | 11/6/2021 | 17/6/2026 | E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging which may aid in crafting more complex attacks. | |
| Modificada | Media (5.5) | 5.4% | — | GstreamerNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+8 | 2/6/2021 | 17/6/2026 | GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. | |
| Modificada | Crítica (9.8) | 2.9% | — | GNU GlibcFedoraproject FedoraNetapp Cloud BackupNetapp E-series Santricity OS Controller+9 | 25/5/2021 | 17/6/2026 | The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified… | |
| Modificada | Alta (8.6) | 17% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+24 | 19/5/2021 | 17/6/2026 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application… | |
| Modificada | Alta (7.5) | 54% | 💥 PoC | Eclipse JettyOracle Autovue FOR Agile Product Lifecycle ManagementOracle Communications Cloud Native Core PolicyOracle Communications Element Manager+17 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | |
| Modificada | Media (5.3) | 82% | 💥 Exploit | Eclipse JettyNetapp Cloud ManagerNetapp E-series Performance AnalyzerNetapp E-series Santricity OS Controller+13 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive… | |
| Modificada | Baja (2.7) | 4.2% | — | Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+19 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. | |
| Modificada | Media (5.3) | 78% | 💥 PoC | Eclipse JettyApache NifiApache SparkNetapp E-series Santricity OS Controller+12 | 26/2/2021 | 17/6/2026 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values,… | |
| Modificada | Media (6.5) | 3.3% | — | DockerDebian LinuxNetapp E-series Santricity OS Controller | 2/2/2021 | 17/6/2026 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing. | |
| Modificada | Media (6.8) | 1.1% | — | DockerDebian LinuxNetapp E-series Santricity OS Controller | 2/2/2021 | 17/6/2026 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under… | |
| Modificada | Alta (7.5) | 3.1% | — | GNU GlibcNetapp E-series Santricity OS ControllerNetapp Ontap Select Deploy Administration UtilityOracle Communications Cloud Native Core Security Edge Protection Proxy+7 | 27/1/2021 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service. |