Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.41% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+11 | 2/10/2021 | 5/8/2026 | prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write. | |
| Modificada | Alta (7) | 2.5% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+8 | 26/9/2021 | 14/7/2026 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of… | |
| Modificada | Media (5.3) | 5.3% | 💥 PoC | Openbsd OpensshNetapp Clustered Data OntapNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+1 | 15/9/2021 | 17/6/2026 | OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not… | |
| Modificada | Alta (7.4) | 50% | 💥 PoC | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Media (5.5) | 0.36% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+1 | 8/8/2021 | 17/6/2026 | btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info. | |
| Modificada | Alta (7.5) | 3.2% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+1 | 8/8/2021 | 17/6/2026 | fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. | |
| Modificada | Alta (7.5) | 3.4% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+1 | 8/8/2021 | 17/6/2026 | net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations. | |
| Modificada | Media (6.5) | 1.2% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+2 | 8/8/2021 | 17/6/2026 | fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection. | |
| Analizada | Alta (7.8) | 0.40% | — | Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+3 | 7/8/2021 | 17/6/2026 | In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation… | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Management Node+15 | 5/8/2021 | 17/6/2026 | libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or… | |
| Modificada | Media (5.3) | 4.9% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+16 | 5/8/2021 | 17/6/2026 | curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to… | |
| Modificada | Baja (3.7) | 6.3% | 💥 PoC | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+29 | 5/8/2021 | 17/6/2026 | libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing… | |
| Modificada | Media (5.3) | 1.9% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+12 | 5/8/2021 | 17/6/2026 | When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's… | |
| Modificada | Media (6.5) | 4.3% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+12 | 5/8/2021 | 17/6/2026 | When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then… | |
| Modificada | Crítica (9.1) | 2.6% | — | GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+3 | 22/7/2021 | 17/6/2026 | The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have… | |
| Modificada | Media (5.5) | 8.8% | — | Systemd Project SystemdFedoraproject FedoraDebian LinuxNetapp HCI Management Node+1 | 20/7/2021 | 17/6/2026 | basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash. | |
| Modificada | Alta (7.8) | 9.7% | 💥 PoC | Linux KernelFedoraproject FedoraDebian LinuxNetapp HCI Management Node+3 | 20/7/2021 | 17/6/2026 | fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05. | |
| Modificada | Media (5.3) | 99% | 💥 Exploit | Eclipse JettyNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB ServicesNetapp Element Plug-in FOR Vcenter Server+14 | 15/7/2021 | 17/6/2026 | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5. | |
| Analizada | Alta (7.8) | 79% | ⚠ Explotación activa💥 Exploit | Netapp C400 FirmwareNetapp C250 FirmwareNetapp H410c FirmwareNetapp H300s Firmware+17 | 7/7/2021 | 17/6/2026 | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space | |
| Modificada | Alta (8.1) | 60% | — | Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+22 | 11/6/2021 | 17/6/2026 | curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at… | |
| Modificada | Media (5.3) | 3.0% | — | Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+18 | 11/6/2021 | 17/6/2026 | curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if… | |
| Modificada | Alta (7.8) | 0.50% | — | Linux KernelNetapp Solidfire Baseboard Management Controller FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+18 | 7/6/2021 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. | |
| Modificada | Media (5.5) | 5.4% | — | GstreamerNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+8 | 2/6/2021 | 17/6/2026 | GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. | |
| Modificada | Alta (7.8) | 0.38% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire & HCI Management Node+8 | 27/5/2021 | 17/6/2026 | kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off… |