Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

81 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.7)3.9%—Oracle JDKOracle JREOracle OpenjdkFedoraproject Fedora+1715/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaMedia (4.8)2.2%—Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+1615/4/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in…
ModificadaBaja (3.7)4.2%—Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+1715/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaBaja (3.7)4.2%—Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+1615/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaBaja (3.7)3.9%—Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+1615/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
ModificadaBaja (3.7)4.1%—Oracle JDKOracle JREOracle OpenjdkNetapp Active IQ Unified Manager+815/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
ModificadaAlta (7.5)1.8%—Netapp Storagegrid13/3/202017/6/2026
StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause a Denial of Service (DoS).
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaMedia (6.5)7.3%—GrafanaRedhat Ceph StorageRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+313/12/201817/6/2026
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
ModificadaCrítica (9.8)1.6%—Netapp Storagegrid Webscale14/11/201817/6/2026
All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on the same network as the StorageGRID Webscale Admin Node via HTTP or to take over services on the Admin Node.
ModificadaAlta (7.5)3.6%—Net-snmpNetapp Cloud BackupNetapp Hyper Converged InfrastructureNetapp Storagegrid Webscale+38/10/201817/6/2026
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (6.5)18%💥 ExploitNet-snmpDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+68/10/201817/6/2026
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (6.1)2.1%—GrafanaNetapp Active IQ Performance Analytics ServicesNetapp Storagegrid Webscale NAS Bridge11/6/201817/6/2026
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
ModificadaAlta (8.3)4.9%—Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Cloud Backup+1319/4/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction…
ModificadaAlta (8.3)4.1%—Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Cloud Backup+1319/4/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction…
ModificadaCrítica (9.8)16%—Apache Http ServerCanonical Ubuntu LinuxDebian LinuxNetapp Cloud Backup+926/3/201817/6/2026
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an…
ModificadaAlta (7.5)70%—Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+326/3/201817/6/2026
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since…
ModificadaMedia (5.9)13%—Apache Http ServerCanonical Ubuntu LinuxNetapp Clustered Data OntapNetapp Santricity Cloud Connector+226/3/201817/6/2026
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could…
ModificadaMedia (5.9)15%—Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+426/3/201817/6/2026
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is…
ModificadaMedia (5.3)9.7%—Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+426/3/201817/6/2026
In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs,…
ModificadaAlta (8.1)85%💥 ExploitApache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+426/3/201817/6/2026
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing…
ModificadaAlta (7.5)17%—Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+426/3/201817/6/2026
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a…
ModificadaAlta (7.5)16%💥 PoCOpenbsd OpensshDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+821/1/201817/6/2026
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
ModificadaAlta (8.3)3.3%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2018/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaAlta (7.5)0.49%—Oracle JDKOracle JRERedhat SatelliteNetapp Active IQ Unified Manager+1618/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks…