Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.31% | — | Tenable Nessus | 3/11/2021 | 17/6/2026 | Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. Tenable has included a fix for this issue in Nessus 10.0.0. The installation files can be obtained from the… | |
| Modificada | Media (6.1) | 41% | 💥 PoC | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+23 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A… | |
| Modificada | Media (6.1) | 8.5% | — | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+24 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as… | |
| Modificada | Media (6.1) | 39% | 💥 PoC | Jqueryui Jquery UIFedoraproject FedoraNetapp H500s FirmwareNetapp H700s Firmware+25 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS… | |
| Modificada | Crítica (9.8) | 2.8% | — | Getcomposer ComposerTenable.sc | 5/10/2021 | 17/6/2026 | Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Alta (7.5) | 65% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+14 | 16/9/2021 | 17/6/2026 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (6.7) | 0.30% | — | Tenable Nessus Agent | 9/9/2021 | 17/6/2026 | Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. This is different than CVE-2021-20117. | |
| Modificada | Media (6.7) | 0.30% | — | Tenable Nessus Agent | 9/9/2021 | 17/6/2026 | Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. This is different than CVE-2021-20118. | |
| Modificada | Alta (7.4) | 50% | 💥 PoC | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Analizada | Alta (7.5) | 46% | — | Debian LinuxApache Http ServerFedoraproject FedoraTenable.sc+2 | 16/8/2021 | 17/6/2026 | A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. | |
| Modificada | Media (6.5) | 1.3% | — | Tenable Nessus | 21/7/2021 | 17/6/2026 | Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host. | |
| Modificada | Media (6.7) | 0.61% | — | Tenable Nessus | 29/6/2021 | 17/6/2026 | Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host. | |
| Modificada | Media (6.7) | 0.47% | — | Tenable Nessus | 28/6/2021 | 17/6/2026 | Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20099. | |
| Modificada | Media (6.7) | 0.43% | — | Tenable Nessus | 28/6/2021 | 17/6/2026 | Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20100. | |
| Modificada | Alta (7.2) | 4.1% | 💥 PoC | Underscorejs UnderscoreDebian LinuxTenable.scFedoraproject Fedora | 29/3/2021 | 17/6/2026 | The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized. | |
| Modificada | Alta (7.4) | 18% | 💥 PoC | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Media (6.7) | 0.35% | — | Tenable Nessus Agent | 19/3/2021 | 17/6/2026 | Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token. | |
| Modificada | Alta (8.6) | 0.45% | — | Tenable Jira Cloud | 10/3/2021 | 17/6/2026 | Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the vulnerabilities' current state. It published in pypi as "tenable-jira-cloud". In tenable-jira-cloud before version 1.1.21, it is possible to run arbitrary commands… | |
| Modificada | Alta (8.8) | 2.1% | — | Tenable.sc | 3/3/2021 | 17/6/2026 | Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization. | |
| Modificada | Media (5.9) | 7.4% | 💥 PoC | OpensslDebian LinuxTenable Nessus Network MonitorTenable.sc+19 | 16/2/2021 | 17/6/2026 | The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is… | |
| Modificada | Alta (7.5) | 51% | 💥 PoC | OpensslDebian LinuxTenable LOG Correlation EngineTenable Nessus Network Monitor+17 | 16/2/2021 | 17/6/2026 | Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output… | |
| Modificada | Media (5.9) | 0.52% | — | Tenable Nessus Amazon Machine Image | 6/2/2021 | 17/6/2026 | Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. |