Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 4.9% | 💥 PoC | OpensslFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap Antivirus Connector+7 | 5/7/2022 | 17/6/2026 | AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the… | |
| Modificada | Alta (7.8) | 5.5% | 💥 Exploit | Linux KernelDebian LinuxCanonical Ubuntu LinuxNetapp H300s Firmware+4 | 4/7/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user… | |
| Modificada | Crítica (9.8) | 46% | 💥 PoC | OpensslNetapp SnapcenterNetapp H410c FirmwareNetapp H300s Firmware+3 | 1/7/2022 | 17/6/2026 | The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory… | |
| Modificada | Alta (7.3) | 95% | — | OpensslDebian LinuxFedoraproject FedoraSiemens Sinec INS+24 | 21/6/2022 | 17/6/2026 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in… | |
| Modificada | Alta (7.8) | 0.33% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H410c Firmware+4 | 9/6/2022 | 17/6/2026 | A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.8) | 2.9% | 💥 PoC | Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+4 | 2/6/2022 | 17/6/2026 | net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. | |
| Modificada | Alta (7.8) | 1.0% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 2/6/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system. | |
| Modificada | Alta (7.8) | 0.54% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxNetapp H410c Firmware+4 | 2/6/2022 | 17/6/2026 | Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the… | |
| Modificada | Alta (7.8) | 0.36% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H410c Firmware+5 | 26/5/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.5) | 2.9% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorNetapp E-series Santricity OS Controller+13 | 25/5/2022 | 17/6/2026 | An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. | |
| Modificada | Alta (7.5) | 6.2% | — | ISC BindNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 19/5/2022 | 17/6/2026 | On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations… | |
| Analizada | Alta (7) | 0.53% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+6 | 18/5/2022 | 26/8/2026 | A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. | |
| Modificada | Alta (7.8) | 0.93% | 💥 PoC | Linux KernelDebian LinuxCanonical Ubuntu LinuxNetapp H300s Firmware+7 | 17/5/2022 | 17/6/2026 | Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions. | |
| Modificada | Crítica (9.1) | 2.8% | — | Pcre2Redhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+8 | 16/5/2022 | 17/6/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers. | |
| Analizada | Crítica (9.1) | 3.4% | — | Pcre2Fedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+9 | 16/5/2022 | 17/6/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching… | |
| Modificada | Alta (7.8) | 0.81% | 💥 PoC | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+6 | 16/5/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.8) | 0.80% | 💥 PoC | Linux KernelDebian LinuxNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+9 | 12/5/2022 | 17/6/2026 | The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. | |
| Modificada | Crítica (9.8) | 64% | — | OpenldapDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 4/5/2022 | 17/6/2026 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping. | |
| Modificada | Media (6.5) | 3.8% | — | Xmlsoft Libxml2Xmlsoft LibxsltFedoraproject FedoraDebian Linux+15 | 3/5/2022 | 17/6/2026 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for… | |
| Analizada | Alta (7.8) | 1.1% | 💥 PoC | Linux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+4 | 2/5/2022 | 2/10/2026 | An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. | |
| Modificada | Alta (7.1) | 0.40% | — | Linux KernelDebian LinuxRedhat Enterprise LinuxNetapp H300s Firmware+7 | 29/4/2022 | 5/8/2026 | A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information. | |
| Modificada | Alta (7) | 0.24% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxNetapp H300s Firmware+7 | 29/4/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.8) | 0.38% | — | Linux KernelNetapp H300e FirmwareNetapp H300s FirmwareNetapp H410c Firmware+5 | 13/4/2022 | 17/6/2026 | drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release. | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management NodeNetapp HCI Compute Node Firmware+9 | 11/4/2022 | 17/6/2026 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | |
| Modificada | Alta (7) | 0.33% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+11 | 8/4/2022 | 17/6/2026 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. |