Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 77% | 💥 PoC | Oracle GraalvmOracle JDKDebian LinuxNetapp 7-mode Transition Tool+12 | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Baja (3.7) | 2.7% | — | Oracle GraalvmOracle Java SENetapp Active IQ Unified ManagerNetapp Cloud Insights Acquisition Unit+12 | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows… | |
| Modificada | Media (5.3) | 2.5% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+13 | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows… | |
| Modificada | Media (5.3) | 3.2% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+13 | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows… | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management NodeNetapp HCI Compute Node Firmware+9 | 11/4/2022 | 17/6/2026 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | |
| Modificada | Alta (7) | 0.33% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+11 | 8/4/2022 | 17/6/2026 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. | |
| Modificada | Media (6.8) | 1.7% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Element Software+12 | 25/3/2022 | 17/6/2026 | A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information. | |
| Analizada | Alta (7.8) | 5.5% | ⚠ Explotación activa💥 Exploit | Netapp H300s FirmwareNetapp H410c FirmwareNetapp H410s FirmwareNetapp H500s Firmware+23 | 3/3/2022 | 17/6/2026 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly. | |
| Modificada | Media (6.5) | 1.2% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxOracle Communications Cloud Native Core Binding Support Function+14 | 2/3/2022 | 17/6/2026 | A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses. | |
| Modificada | Alta (7.5) | 5.1% | — | Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+31 | 26/2/2022 | 17/6/2026 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | |
| Modificada | Media (5.9) | 0.67% | — | Linux KernelNetapp Cloud Volumes Ontap MediatorNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage Node+13 | 26/2/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session. | |
| Analizada | Alta (7.4) | 6.9% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+17 | 18/2/2022 | 30/7/2026 | A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this… | |
| Modificada | Media (4.7) | 0.36% | — | Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Element Software+8 | 16/2/2022 | 17/6/2026 | A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality. | |
| Modificada | Media (5.3) | 3.2% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (5.3) | 3.5% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 3.5% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 3.3% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+12 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u321, 8u311; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 3.8% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows… | |
| Modificada | Media (5.3) | 7.7% | 💥 PoC | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 2.8% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 3.5% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 2.8% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 3.4% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+15 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 8.3% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+16 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… | |
| Modificada | Media (5.3) | 2.9% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+16 | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated… |