Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

386 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)3.0%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+2229/9/202117/6/2026
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and…
ModificadaAlta (7.5)4.5%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Cloud Backup+2529/9/202117/6/2026
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly…
ModificadaAlta (7.5)7.4%—Apache Santuario XML Security FOR JavaApache CXFApache TomeeDebian Linux+1419/9/202125/8/2026
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a…
AnalizadaAlta (7.5)63%—Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+916/9/202117/6/2026
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
ModificadaAlta (7.5)65%—Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1416/9/202117/6/2026
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaAlta (7.4)50%💥 PoCOpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+2824/8/202117/6/2026
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a…
ModificadaCrítica (9.8)88%—OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+2724/8/202117/6/2026
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the…
ModificadaAlta (7.5)6.7%—JsoupQuarkusOracle Banking Trade FinanceOracle Banking Treasury Management+1218/8/202117/6/2026
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete…
ModificadaAlta (7.5)14%—Nodejs Node.jsOracle GraalvmOracle JD Edwards Enterpriseone ToolsOracle Peoplesoft Enterprise Peopletools+316/8/202117/6/2026
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
ModificadaMedia (5.3)15%—Nodejs Node.jsOracle GraalvmOracle JD Edwards Enterpriseone ToolsOracle Mysql Cluster+416/8/202117/6/2026
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
ModificadaCrítica (9.8)22%—Nodejs Node.jsNetapp Active IQ Unified ManagerNetapp Nextgen APINetapp Oncommand Insight+616/8/202117/6/2026
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in…
ModificadaMedia (5.4)1.3%—CkeditorDebian LinuxFedoraproject FedoraOracle Application Express+813/8/202117/6/2026
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It…
ModificadaMedia (5.4)1.2%—CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+612/8/202117/6/2026
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary…
ModificadaMedia (5.4)1.2%—CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+912/8/202117/6/2026
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It…
ModificadaAlta (7.5)9.8%—Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Management Node+155/8/202117/6/2026
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or…
ModificadaMedia (5.3)4.9%—Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+165/8/202117/6/2026
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to…
ModificadaBaja (3.7)6.3%💥 PoCHaxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+295/8/202117/6/2026
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing…
ModificadaMedia (5.3)1.2%—Oracle Peoplesoft Enterprise Peopletools21/7/202117/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
ModificadaMedia (4.3)0.67%—Oracle Peoplesoft Enterprise Peopletools21/7/202117/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful…
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaAlta (7.5)13%—Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+3013/7/202117/6/2026
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
ModificadaAlta (7.5)11%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Apis+2313/7/202117/6/2026
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
ModificadaAlta (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+2013/7/202117/6/2026
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModificadaAlta (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+2213/7/202117/6/2026
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModificadaAlta (8.6)17%—Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+2419/5/202117/6/2026
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application…