Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.30%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+59/6/202117/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.35%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+79/6/202117/6/2026
Out of bounds read in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.8)0.32%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+49/6/202117/6/2026
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaMedia (4.4)0.30%—Intel BiosSiemens Simatic Ipc547g FirmwareNetapp Cloud BackupNetapp AFF Bios+59/6/202117/6/2026
Out of bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.35%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+159/6/202117/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)3.6%—Oracle JDKOracle JREDebian LinuxFedoraproject Fedora+722/4/202117/6/2026
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to…
ModificadaMedia (5.9)3.5%—Oracle JDKOracle JREDebian LinuxFedoraproject Fedora+822/4/202117/6/2026
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to…
ModificadaBaja (3.7)3.1%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+71/4/202117/6/2026
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server…
ModificadaMedia (5.3)5.3%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+81/4/202117/6/2026
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP…
ModificadaAlta (7.1)3.4%—Openbsd OpensshFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+55/3/202117/6/2026
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
ModificadaMedia (5.5)0.35%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+417/2/202117/6/2026
An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to the backend driver, and the backend driver then loops over the…
ModificadaCrítica (9.8)4.3%—Netapp HCI Management NodeNetapp SolidfireNetapp HCI Storage NodeNetapp Element OS8/1/202117/6/2026
Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrary code execution.
ModificadaMedia (5.5)1.3%—GNU BinutilsRedhat Enterprise LinuxNetapp HCI Compute Node FirmwareNetapp Cloud Backup+44/1/202117/6/2026
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
ModificadaMedia (5.5)1.2%—GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+44/1/202117/6/2026
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
ModificadaMedia (5.5)1.2%—GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+44/1/202117/6/2026
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
ModificadaMedia (6.1)1.1%—GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+44/1/202117/6/2026
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.
ModificadaMedia (5.5)1.1%—GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+44/1/202117/6/2026
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
ModificadaAlta (8.8)0.39%—XENLinux KernelNetapp HCI Compute Node BiosNetapp Solidfire & HCI Management Node+215/12/202017/6/2026
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to run if the frontend quickly toggles between the states connect and…
ModificadaAlta (7.5)4.6%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1314/12/202017/6/2026
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
ModificadaAlta (7.5)9.8%—Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+1814/12/202017/6/2026
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
ModificadaBaja (3.7)3.9%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1814/12/202017/6/2026
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
ModificadaMedia (5.9)7.1%💥 PoCOpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaBaja (3.6)0.41%—Linux KernelDebian LinuxNetapp 500f FirmwareNetapp A250 Firmware+428/11/202017/6/2026
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
ModificadaAlta (7)0.61%💥 PoCLinux KernelNetapp Cloud BackupNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+328/11/202017/6/2026
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.
ModificadaAlta (7)0.46%—Linux KernelNetapp HCI Management NodeNetapp SolidfireNetapp HCI Compute Node+128/11/202017/6/2026
An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe.
Orbitaley — Vulnerabilidades