Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.68%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.
ModificadaMedia (4.6)0.69%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver.
ModificadaMedia (4.6)0.76%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c driver.
ModificadaMedia (4.6)0.66%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+319/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.
ModificadaMedia (4.6)0.77%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.
ModificadaMedia (4.6)0.76%—Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+519/8/201917/6/2026
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.
ModificadaMedia (5.5)0.76%—Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+616/8/201917/6/2026
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
ModificadaAlta (7.5)25%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each…
ModificadaAlta (7.5)28%—Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+1913/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The…
ModificadaMedia (6.5)56%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1513/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and…
ModificadaAlta (7.5)87%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1813/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a…
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+2413/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can…
ModificadaAlta (7.5)82%—Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1613/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
ModificadaAlta (7.5)83%—Apple SwiftnioApache Traffic ServerDebian LinuxNodejs Node.js13/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
ModificadaAlta (7.5)60%💥 PoCApple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+1613/8/201917/6/2026
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to…
ModificadaMedia (5.5)1.5%—GNU BinutilsOpensuse LeapCanonical Ubuntu LinuxNetapp HCI Management Node+130/7/201917/6/2026
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
ModificadaMedia (5.5)1.1%—GNU BinutilsGNU Binutils GoldNetapp HCI Management NodeNetapp Solidfire23/7/201917/6/2026
GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header…
AnalizadaAlta (7.8)52%⚠ Explotación activa💥 ExploitLinux KernelDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1817/7/201917/6/2026
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges…
ModificadaCrítica (9.8)2.3%—Healthnode Hospital Management System Project Healthnode Hospital Management System19/6/201917/6/2026
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
ModificadaCrítica (9.8)6.8%—Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1914/6/201917/6/2026
A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.
ModificadaAlta (7.5)57%💥 ExploitGrandnode5/6/201917/6/2026
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in…
ModificadaAlta (7.5)3.9%—Linux KernelNetapp AFF A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+33/6/201917/6/2026
An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).
ModificadaAlta (8.8)5.6%—Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxNetapp A700s Firmware+83/6/201917/6/2026
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
ModificadaAlta (7.8)50%—Haxx LibcurlOpensuse LeapFedoraproject FedoraDebian Linux+728/5/201917/6/2026
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
AnalizadaMedia (4.3)2.5%—Systemd Project SystemdNetapp Cn1610 FirmwareNetapp SnapprotectNetapp Solidfire & HCI Management Node17/5/201917/6/2026
systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.