Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+6 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI… | |
| Modificada | Media (5.9) | 1.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+6 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as… | |
| Modificada | Alta (8.8) | 2.2% | — | Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerBroadcom Brocade Fabric Operating System Firmware+5 | 30/3/2023 | 17/6/2026 | A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw… | |
| Modificada | Alta (8.8) | 2.0% | — | Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+5 | 30/3/2023 | 17/6/2026 | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation… | |
| Modificada | Alta (7) | 0.28% | — | Linux KernelDebian LinuxNetapp A700s FirmwareNetapp 8300 Firmware+8 | 27/3/2023 | 17/6/2026 | In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing… | |
| Modificada | Alta (7.1) | 17% | — | Redhat Enterprise LinuxLinux KernelNetapp H500s FirmwareNetapp H700s Firmware+5 | 27/3/2023 | 17/9/2026 | A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service. | |
| Analizada | Alta (7.8) | 7.9% | ⚠ Explotación activa💥 Exploit | Debian LinuxNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+4 | 22/3/2023 | 17/6/2026 | A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on… | |
| Analizada | Media (4.7) | 0.33% | — | Debian LinuxLinux KernelNetapp H300s FirmwareNetapp H500s Firmware+3 | 25/2/2023 | 17/6/2026 | In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device. | |
| Modificada | Media (6.5) | 1.7% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp H300s Firmware+5 | 23/2/2023 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain"… | |
| Modificada | Media (6.5) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is… | |
| Modificada | Crítica (9.1) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL.… | |
| Analizada | Alta (7.8) | 0.43% | — | Netapp H410s FirmwareNetapp H410c FirmwareNetapp H700s FirmwareNetapp H500s Firmware+2 | 11/1/2023 | 1/9/2026 | There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as… | |
| Modificada | Alta (7.8) | 0.34% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames. | |
| Modificada | Alta (7.1) | 0.32% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink packet. | |
| Modificada | Alta (7.8) | 0.30% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from Wi-Fi management frames. | |
| Modificada | Alta (7.8) | 0.33% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+3 | 18/12/2022 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames. | |
| Modificada | Media (6.5) | 1.9% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+4 | 5/12/2022 | 17/6/2026 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or… | |
| Modificada | Crítica (9.8) | 4.7% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+5 | 5/12/2022 | 17/6/2026 | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and… | |
| Modificada | Alta (7.8) | 0.77% | 💥 PoC | Linux KernelFedoraproject FedoraNetapp H410c FirmwareNetapp H300s Firmware+4 | 27/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. | |
| Modificada | Alta (7) | 0.26% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 27/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event. | |
| Modificada | Media (6.4) | 0.71% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device. | |
| Modificada | Media (4.7) | 0.29% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call. | |
| Modificada | Alta (7) | 0.33% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb_device_open race condition that leads to a use-after-free. | |
| Modificada | Alta (7) | 0.31% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 25/11/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected. | |
| Analizada | Alta (7) | 0.33% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+2 | 25/11/2022 | 13/8/2026 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops. |