Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.34%—Broadcom Fabric Operating System25/9/202017/6/2026
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging.
ModificadaCrítica (9.8)1.3%—Broadcom Fabric Operating System25/9/202017/6/2026
Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability.
ModificadaMedia (6.5)1.0%—Broadcom Fabric Operating System25/9/202017/6/2026
Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files.
ModificadaAlta (8.8)1.0%—Broadcom Fabric Operating System25/9/202017/6/2026
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.
ModificadaMedia (6.1)0.77%—Broadcom Fabric Operating System25/9/202017/6/2026
Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers
ModificadaAlta (7.5)1.4%—Broadcom Fabric Operating System25/9/202017/6/2026
A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.
ModificadaMedia (5.4)0.51%—Broadcom Fabric Operating System25/9/202017/6/2026
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account.
AnalizadaAlta (7.4)13%💥 PoCOpenbsd OpensshNetapp A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+524/7/202017/6/2026
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking…
ModificadaMedia (6.5)2.0%—Gnome BalsaGnome Glib-networkingCanonical Ubuntu LinuxFedoraproject Fedora+228/5/202017/6/2026
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications…
ModificadaMedia (5.5)0.57%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+827/5/202017/6/2026
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
ModificadaMedia (5.5)0.62%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1427/5/202017/6/2026
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
ModificadaAlta (7)1.0%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1527/5/202017/6/2026
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
ModificadaAlta (7.5)4.4%—OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1428/4/202017/6/2026
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
ModificadaAlta (7.5)53%💥 PoCOpensslDebian LinuxFreebsdFedoraproject Fedora+2221/4/202017/6/2026
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from…
ModificadaMedia (6.1)57%—Apache Http ServerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+102/4/202017/6/2026
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
ModificadaAlta (7.1)0.66%—Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ Unified Manager+56/2/202017/6/2026
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
ModificadaAlta (7.5)1.5%—Broadcom Fabric Operating System5/2/202017/6/2026
Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an external server.
ModificadaAlta (7.5)1.4%—Broadcom Fabric Operating System5/2/202017/6/2026
Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configuring the ESRS client.
ModificadaAlta (7.5)3.5%—Linux KernelCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp Data Availability Services+1218/11/201917/6/2026
A memory leak in the fastrpc_dma_buf_attach() function in drivers/misc/fastrpc.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering dma_get_sgtable() failures, aka CID-fc739a058d99.
ModificadaMedia (4.6)0.90%—Linux KernelOracle Sd-wan EdgeCanonical Ubuntu LinuxFedoraproject Fedora+1418/11/201917/6/2026
Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.
ModificadaAlta (7.5)3.4%—Linux KernelCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp AFF Baseboard Management Controller+1118/11/201917/6/2026
A memory leak in the adis_update_scan_mode_burst() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-9c0530e898f3.
ModificadaAlta (7.5)3.6%—Linux KernelNetapp Active IQ Unified ManagerNetapp AFF Baseboard Management ControllerNetapp Cloud Backup+1218/11/201917/6/2026
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.
ModificadaBaja (3.3)0.79%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1418/11/201917/6/2026
Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
ModificadaMedia (4.7)0.45%—Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+1318/11/201917/6/2026
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b.
ModificadaAlta (7.5)3.3%—Linux KernelCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp AFF Baseboard Management Controller+1118/11/201917/6/2026
A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy_from_iter_full() failures, aka CID-bbe692e349e2.