Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.7)0.16%—Intel Ethernet Controller Administrative ToolsAI16/5/202417/6/2026
Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (4.4)0.17%—Hitachi OPS Center AdministratorAI23/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.
AplazadaMedia (5.3)0.44%—Inisev Backup MigrationAI18/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.
AnalizadaCrítica (9.8)0.32%—Netapp Ontap Select Deploy Administration Utility17/4/202417/6/2026
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.
AnalizadaAlta (8.8)0.43%—Netapp Ontap Select Deploy Administration Utility17/4/202417/6/2026
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully exploited could allow a read-only user to escalate their privileges.
En análisisAlta (7.3)88%💥 ExploitGNU GlibcNetapp Active IQ Unified ManagerDebian LinuxNetapp HCI H300s Firmware+917/4/202417/6/2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
AnalizadaMedia (5.9)0.40%—Inisev Social Media Share Buttons & Social Sharing Icons17/4/202417/6/2026
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AnalizadaMedia (6.1)0.17%—Oracle Peoplesoft Enterprise HCM Benefits Administration16/4/202417/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise HCM…
AplazadaMedia (6.5)0.46%—Lenovo Xclarity AdministratorAI5/4/202417/6/2026
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
AnalizadaAlta (8.6)36%—Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+1027/3/202417/6/2026
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.…
AnalizadaMedia (6.3)1.7%—Haxx CurlApple MacosNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+827/3/202417/6/2026
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
AnalizadaBaja (3.5)1.7%—Haxx CurlFedoraproject FedoraApple MacosNetapp Ontap+627/3/202417/6/2026
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled.…
ModificadaMedia (5.5)0.58%—Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+1018/3/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h variable after this call as it can change skb->head.
AnalizadaMedia (5.5)0.33%—Linux KernelDebian LinuxNetapp Ontap Select Deploy Administration UtilityNetapp Ontap Tools+1618/3/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim() syzbot pointed out [1] that NEXTHDR_FRAGMENT handling is broken. Reading frag_off can only be done if we pulled enough bytes to skb->head. Currently we might access garbage.
AnalizadaMedia (5.4)0.44%—Inisev Ultimate Posts Widget11/3/202417/6/2026
The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…
AnalizadaMedia (6.5)0.50%—Inisev Enhanced Text Widget11/3/202417/6/2026
The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…
ModificadaMedia (5.5)0.44%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+429/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
AnalizadaAlta (7.5)1.1%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+529/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
AnalizadaMedia (5.3)0.81%—MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+529/2/202417/6/2026
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
ModificadaAlta (7.8)0.17%—Administrative Tools FOR Intel Network AdaptersIntel Ethernet Connections Boot Utility, Preboot Images, AND EFI Drivers14/2/202417/6/2026
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)1.8%—Malwarebytes Binisoft Windows Firewall Control4/2/202417/6/2026
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
ModificadaCrítica (9.8)1.0%—Dmparekh Wordpress Database Administrator16/1/202417/6/2026
The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
ModificadaCrítica (9.8)0.57%—Inis Project Inis9/1/202417/6/2026
A vulnerability classified as critical has been found in Inis up to 2.0.1. Affected is an unknown function of the file /app/api/controller/default/Sqlite.php. The manipulation of the argument sql leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250110 is the identifier assigned…
ModificadaAlta (7.5)0.61%—Inis Project Inis9/1/202417/6/2026
A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/controller/default/File.php of the component GET Request Handler. The manipulation of the argument path leads to path traversal: '../filedir'. The exploit has been disclosed…
ModificadaAlta (8.8)0.48%—Inis Project Inis8/1/202417/6/2026
A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controller/default/Proxy.php. The manipulation of the argument p_url leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to…
Orbitaley — Vulnerabilidades