Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.42% | — | Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+2 | 12/11/2020 | 17/6/2026 | Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.42% | — | Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+2 | 12/11/2020 | 17/6/2026 | Out of bounds write in Intel BIOS platform sample code for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.42% | — | Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+2 | 12/11/2020 | 17/6/2026 | Use of potentially dangerous function in Intel BIOS platform sample code for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel BiosNetapp Cloud BackupNetapp Fas/aff BiosNetapp HCI Compute Node Bios+2 | 12/11/2020 | 17/6/2026 | Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.52% | — | Intel MicrocodeNetapp Clustered Data OntapNetapp HCI Compute Node BiosNetapp HCI Storage Node Bios+13 | 12/11/2020 | 17/6/2026 | Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.44% | — | Intel MicrocodeNetapp Clustered Data OntapNetapp HCL Compute Node BiosNetapp HCI Storage Node Bios+3 | 12/11/2020 | 17/6/2026 | Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 3.6% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+9 | 22/10/2020 | 17/6/2026 | In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow. | |
| Analizada | Media (5.3) | 3.2% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Analizada | Baja (3.1) | 2.7% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.1) | 2.5% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Media (4.2) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analizada | Baja (3.7) | 2.3% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+13 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Analizada | Baja (3.7) | 3.8% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 2.4% | — | Linux KernelDebian LinuxNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+3 | 13/10/2020 | 17/6/2026 | A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this… | |
| Modificada | Alta (7.2) | 6.4% | — | PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+4 | 27/9/2020 | 17/6/2026 | http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | |
| Modificada | Alta (7.8) | 0.67% | — | Linux KernelNetapp Cloud BackupNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+2 | 10/9/2020 | 17/6/2026 | get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use… | |
| Analizada | Alta (7.4) | 13% | 💥 PoC | Openbsd OpensshNetapp A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+5 | 24/7/2020 | 17/6/2026 | scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking… | |
| Modificada | Media (5.9) | 2.1% | — | Openbsd OpensshNetapp AFF A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+5 | 29/6/2020 | 17/6/2026 | The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6… | |
| Modificada | Media (5.5) | 0.57% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+8 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. | |
| Modificada | Media (5.5) | 0.62% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+14 | 27/5/2020 | 17/6/2026 | SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. | |
| Modificada | Alta (7) | 1.0% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+15 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. | |
| Modificada | Media (6.7) | 0.80% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud BackupNetapp HCI Baseboard Management Controller+6 | 29/4/2020 | 17/6/2026 | usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. | |
| Modificada | Alta (7.5) | 2.1% | — | NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+13 | 17/4/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp. | |
| Modificada | Media (6.7) | 1.0% | — | E2fsprogs Project E2fsprogsFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+3 | 8/1/2020 | 17/6/2026 | A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability. |