Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.75% | — | Robindkumar Wr-age-verificationAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age Verification wr-age-verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through <= 2.0.0. | |
| Aplazada | Alta (8.5) | 0.52% | — | Robindkumar Wr-age-verificationAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age Verification wr-age-verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through <= 2.0.0. | |
| Aplazada | Alta (7.5) | 2.1% | — | ISC BindAI | 23/7/2024 | 17/6/2026 | Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and… | |
| Aplazada | Alta (7.5) | 2.1% | — | ISC BindAI | 23/7/2024 | 17/6/2026 | If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through… | |
| Aplazada | Alta (7.5) | 2.1% | — | ISC BindAI | 23/7/2024 | 17/6/2026 | Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0… | |
| Aplazada | Alta (7.5) | 4.7% | — | ISC BindAI | 23/7/2024 | 17/6/2026 | A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and… | |
| Aplazada | Media (6.5) | 0.31% | — | Sharabindu QR Code ComposerAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sharabindu QR Code Composer allows Stored XSS.This issue affects QR Code Composer: from n/a through 2.0.3. | |
| Analizada | Alta (7.5) | 74% | — | Netapp HCI Baseboard Management ControllerNetapp Active IQ Unified ManagerNetapp Bootstrap OSPowerdns Recursor+4 | 14/2/2024 | 17/6/2026 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an… | |
| Modificada | Alta (7.5) | 100% | — | Redhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+9 | 14/2/2024 | 17/6/2026 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the… | |
| Modificada | Alta (7.5) | 1.1% | — | ISC BindNetapp Active IQ Unified Manager | 13/2/2024 | 17/6/2026 | To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later… | |
| Modificada | Media (5.3) | 0.63% | — | ISC BindNetapp Active IQ Unified Manager | 13/2/2024 | 17/6/2026 | If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1. | |
| Modificada | Alta (7.5) | 1.2% | — | Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and… | |
| Modificada | Alta (7.5) | 1.2% | — | Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: | |
| Modificada | Alta (7.5) | 1.3% | — | Netapp OntapFedoraproject FedoraISC Bind | 13/2/2024 | 17/6/2026 | The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative… | |
| Modificada | Alta (7.5) | 2.2% | — | ISC BindFedoraproject FedoraDebian LinuxNetapp H300s Firmware+4 | 20/9/2023 | 17/6/2026 | A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1… | |
| Modificada | Alta (7.5) | 2.9% | — | ISC BindFedoraproject FedoraDebian Linux | 20/9/2023 | 17/6/2026 | The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to… | |
| Modificada | Alta (7.5) | 2.5% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33… | |
| Modificada | Alta (7.5) | 0.88% | — | ISC BindNetapp Active IQ Unified ManagerNetapp H500s FirmwareNetapp H700s Firmware+3 | 21/6/2023 | 17/6/2026 | A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and… | |
| Modificada | Alta (7.5) | 3.8% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of… | |
| Modificada | Media (4.7) | 0.35% | — | Fasterxml Jackson-databind | 14/6/2023 | 17/6/2026 | jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to… | |
| Modificada | Media (5.3) | 1.3% | — | Oracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core PolicyOracle Mysql ConnectorsNetapp Active IQ Unified Manager+2 | 18/4/2023 | 17/6/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… | |
| Modificada | Alta (7.5) | 1.1% | — | Fasterxml Jackson-databind | 18/3/2023 | 17/6/2026 | jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization. | |
| Modificada | Alta (7.5) | 16% | — | ISC Bind | 26/1/2023 | 17/6/2026 | This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are… | |
| Modificada | Alta (7.5) | 49% | — | ISC Bind | 26/1/2023 | 17/6/2026 | BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through… | |
| Modificada | Alta (7.5) | 19% | — | ISC Bind | 26/1/2023 | 17/6/2026 | Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between… |