Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

155 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)23%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+619/1/202117/6/2026
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
ModificadaMedia (5.3)4.7%—WiresharkOracle ZFS Storage Appliance KIT21/12/202017/6/2026
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
ModificadaMedia (5.3)2.5%—WiresharkFedoraproject FedoraDebian LinuxOracle ZFS Storage Appliance KIT11/12/202017/6/2026
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
ModificadaMedia (5.3)2.7%—WiresharkFedoraproject FedoraOracle ZFS Storage Appliance KIT11/12/202017/6/2026
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
ModificadaMedia (5.3)2.9%—WiresharkFedoraproject FedoraOracle ZFS Storage Appliance KIT11/12/202017/6/2026
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
ModificadaMedia (5.3)3.0%—WiresharkFedoraproject FedoraDebian LinuxOracle ZFS Storage Appliance KIT11/12/202017/6/2026
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
ModificadaAlta (7.5)4.7%—Pytest PYFedoraproject FedoraOracle ZFS Storage Appliance KIT9/12/202017/6/2026
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
ModificadaMedia (6.1)4.0%—LxmlRedhat Software CollectionsRedhat Enterprise LinuxDebian Linux+43/12/202017/6/2026
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
ModificadaAlta (7.5)4.0%—WiresharkFedoraproject FedoraOpensuse LeapOracle ZFS Storage Appliance KIT6/10/202017/6/2026
In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.
ModificadaMedia (6.5)2.3%—Python Urllib3Canonical Ubuntu LinuxDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+130/9/202017/6/2026
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
ModificadaAlta (7.2)6.4%—PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+427/9/202017/6/2026
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
ModificadaAlta (7.5)3.3%—Djangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraOracle ZFS Storage Appliance KIT1/9/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
ModificadaAlta (7.5)4.0%—Djangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraOracle ZFS Storage Appliance KIT1/9/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static…
AnalizadaCrítica (10)99%⚠ Explotación activa💥 ExploitMicrosoft Windows Server 1903Microsoft Windows Server 1909Microsoft Windows Server 2004Microsoft Windows Server 2008+1117/8/202017/6/2026
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the…
ModificadaMedia (6.5)2.6%—WiresharkFedoraproject FedoraOpensuse LeapOracle ZFS Storage Appliance KIT13/8/202017/6/2026
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
ModificadaAlta (7.5)89%—Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+217/8/202017/6/2026
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
AnalizadaAlta (7.5)56%—Apache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxOpensuse Leap+97/8/202017/6/2026
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for…
ModificadaCrítica (9.8)90%💥 ExploitApache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxDebian Linux+97/8/202017/6/2026
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
ModificadaAlta (7.5)6.3%—PythonOpensuse LeapDebian LinuxFedoraproject Fedora+413/7/20207/10/2026
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
ModificadaMedia (6.5)2.3%—Net-snmpOracle ZFS Storage Appliance KIT25/6/202017/6/2026
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.
ModificadaMedia (4.9)3.4%—NTPOpensuse LeapNetapp Cloud BackupNetapp Steelstore Cloud Integrated Storage+1224/6/202017/6/2026
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
ModificadaAlta (7.5)4.4%—SqliteFedoraproject FedoraDebian LinuxOracle Communications Messaging Server+86/6/202017/6/2026
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
ModificadaMedia (6.1)2.9%—Djangoproject DjangoFedoraproject FedoraCanonical Ubuntu LinuxNetapp SRA Plugin+33/6/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
ModificadaMedia (5.9)6.1%💥 PoCDjangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraNetapp SRA Plugin+33/6/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
ModificadaMedia (5.5)0.57%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+827/5/202017/6/2026
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.