Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.4% | — | NTPSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 FirmwareFreebsd+3 | 30/1/2017 | 17/6/2026 | NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. | |
| Analizada | Alta (7.5) | 6.1% | — | Netapp Clustered Data OntapNetapp Data Ontap Operating IN 7-modeNetapp Oncommand BalanceNetapp Oncommand Performance Manager+2 | 6/1/2017 | 17/6/2026 | An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash. | |
| Analizada | Alta (7) | 84% | ⚠ Explotación activa💥 Exploit | Canonical Ubuntu LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 10/11/2016 | 17/6/2026 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW." | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | |
| Modificada | Alta (7.7) | 5.7% | — | NTPSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 FirmwareNetapp Clustered Data Ontap+2 | 26/1/2016 | 17/6/2026 | NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key." | |
| Modificada | Media (4) | 0.95% | — | Netapp Oncommand Balance | 6/2/2015 | 17/6/2026 | NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related to cleartext storage. | |
| Modificada | Alta (10) | 2.9% | — | Netapp Oncommand Balance | 6/2/2015 | 17/6/2026 | NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors. | |
| Analizada | Alta (8.8) | 83% | ⚠ Explotación activa💥 Exploit | Redhat Jboss Enterprise Application PlatformNetapp Oncommand BalanceNetapp Oncommand InsightNetapp Oncommand Unified Manager | 5/8/2010 | 16/6/2026 | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security… |