Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

150 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.4)25%⚠ Explotación activa💥 PoCLinux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+511/2/202217/6/2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user…
AnalizadaAlta (7.8)0.41%—Linux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+711/2/202211/9/2026
drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
ModificadaAlta (7.8)1.0%💥 PoCLinux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+629/1/202217/6/2026
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
ModificadaAlta (7.8)0.97%—Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+525/1/202217/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The…
ModificadaAlta (7)0.31%—Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+1118/1/202217/6/2026
A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This…
ModificadaAlta (7.8)1.9%💥 PoCLinux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+714/1/202217/6/2026
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
AnalizadaAlta (7.5)3.6%💥 PoCLinux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+2225/12/20215/8/2026
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
ModificadaAlta (7.8)0.55%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware+723/12/202117/6/2026
In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
AnalizadaAlta (7)0.71%💥 PoCLinux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux+822/12/20215/8/2026
A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
ModificadaAlta (7.5)0.88%—Ksmbd Project KsmbdNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+516/12/202117/6/2026
The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. When…
ModificadaAlta (7.5)50%💥 PoCOpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+1214/12/202117/6/2026
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as…
ModificadaAlta (7.8)0.52%—Linux KernelNetapp Cloud BackupNetapp H410c FirmwareNetapp H300s Firmware+68/12/202117/6/2026
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.
ModificadaMedia (4.6)0.69%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1117/11/202117/6/2026
In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
ModificadaMedia (6.7)0.55%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+717/11/202117/6/2026
In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.
ModificadaCrítica (9.8)3.6%—BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+815/11/202117/6/2026
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
ModificadaMedia (5.5)0.43%—BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+815/11/202117/6/2026
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
ModificadaMedia (5.5)0.41%—BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+815/11/202117/6/2026
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
ModificadaMedia (5.3)0.62%—BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+815/11/202117/6/2026
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
ModificadaMedia (5.5)0.41%—BusyboxFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+815/11/202117/6/2026
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
ModificadaCrítica (9.8)58%💥 PoCLinux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+52/11/202117/6/2026
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
ModificadaAlta (8.8)3.7%💥 ExploitLinux KernelNetapp Cloud BackupNetapp H300s FirmwareNetapp H500s Firmware+52/11/202117/6/2026
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
ModificadaAlta (7.8)0.49%—Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+528/10/202117/6/2026
An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate privileges, aka CID-a3727a8bac0a. This occurs because of an attempt to access the subjective…
ModificadaMedia (5.3)11%—ISC BindDebian LinuxFedoraproject FedoraNetapp H300s Firmware+1127/10/202117/6/2026
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause…
ModificadaMedia (6.1)41%💥 PoCJqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+2326/10/202125/8/2026
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A…
ModificadaMedia (6.1)8.5%—Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+2426/10/202125/8/2026
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as…