Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 13% | — | ISC Bind | 26/1/2023 | 17/6/2026 | Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during… | |
| Modificada | Media (4.4) | 0.21% | — | Oracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Policy | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the… | |
| Analizada | Alta (8.1) | 3.5% | — | Debian LinuxNetapp Active IQ Unified ManagerFasterxml Jackson-databindOracle Retail Merchandising System+1 | 26/12/2022 | 17/6/2026 | A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and… | |
| Modificada | Alta (7.5) | 3.4% | — | Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation | 2/10/2022 | 17/6/2026 | In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. | |
| Modificada | Alta (7.5) | 3.4% | — | Fasterxml Jackson-databindQuarkusDebian LinuxNetapp Oncommand Workflow Automation | 2/10/2022 | 17/6/2026 | In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. | |
| Modificada | Alta (7.5) | 1.9% | — | ISC BindFedoraproject Fedora | 21/9/2022 | 17/6/2026 | By sending specific queries to the resolver, an attacker can cause named to crash. | |
| Modificada | Alta (7.5) | 3.0% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager | 21/9/2022 | 1/9/2026 | By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. | |
| Modificada | Alta (7.5) | 3.2% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager | 21/9/2022 | 1/9/2026 | By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. | |
| Modificada | Alta (7.5) | 2.1% | — | ISC Bind | 21/9/2022 | 17/6/2026 | An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service. | |
| Modificada | Alta (8.2) | 1.4% | — | ISC Bind | 21/9/2022 | 17/6/2026 | The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process. | |
| Modificada | Media (5.3) | 2.2% | — | ISC BindDebian LinuxFedoraproject Fedora | 21/9/2022 | 1/9/2026 | By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service. | |
| Modificada | Alta (7.5) | 6.2% | — | ISC BindNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 19/5/2022 | 17/6/2026 | On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (5.5) | 0.30% | — | Linux KernelFedoraproject FedoraOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure Function+1 | 25/3/2022 | 17/6/2026 | A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS). | |
| Modificada | Media (6.8) | 1.7% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Element Software+12 | 25/3/2022 | 17/6/2026 | A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information. | |
| Modificada | Alta (8) | 1.6% | — | Linux KernelFedoraproject FedoraNetapp H300e FirmwareNetapp H300s Firmware+6 | 25/3/2022 | 17/6/2026 | An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system. | |
| Modificada | Alta (7.8) | 0.54% | — | Linux KernelOracle Communications Cloud Native Core Binding Support FunctionDebian LinuxBroadcom Brocade Fabric Operating System Firmware+5 | 23/3/2022 | 17/6/2026 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control… | |
| Modificada | Media (6.8) | 3.4% | — | ISC BindFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+8 | 23/3/2022 | 17/6/2026 | BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The… | |
| Modificada | Alta (7.5) | 1.3% | — | ISC BindNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+5 | 23/3/2022 | 17/6/2026 | Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check. | |
| Modificada | Media (5.3) | 2.7% | — | ISC BindFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+7 | 23/3/2022 | 17/6/2026 | BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection. | |
| Modificada | Alta (7.5) | 1.3% | — | ISC BindNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+5 | 22/3/2022 | 17/6/2026 | When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 | |
| Analizada | Alta (7.8) | 1.2% | — | Linux KernelFedoraproject FedoraRedhat Build OF QuarkusRedhat Developer Tools+26 | 18/3/2022 | 26/8/2026 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation. | |
| Modificada | Media (6.5) | 0.45% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+500 | 11/3/2022 | 17/6/2026 | Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 0.51% | — | Intel Atom P5921bIntel Atom P5931bIntel Atom P5942bIntel Atom P5962b+454 | 11/3/2022 | 17/6/2026 | Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.5) | 4.9% | — | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |