Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
566 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.65% | — | FreebsdNetapp Clustered Data Ontap | 1/8/2023 | 17/6/2026 | A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service. | |
| Modificada | Alta (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 17/7/2023 | 17/6/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modificada | Alta (7.8) | 0.20% | — | Redhat Advanced Cluster Management FOR Kubernetes | 5/6/2023 | 17/6/2026 | The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict… | |
| Modificada | Alta (7.5) | 1.9% | — | OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+7 | 30/5/2023 | 17/6/2026 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. | |
| Modificada | Baja (3.7) | 2.2% | — | Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+5 | 26/5/2023 | 17/6/2026 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which… | |
| Modificada | Media (5.9) | 1.8% | — | Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+6 | 26/5/2023 | 17/6/2026 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private… | |
| Modificada | Media (5.9) | 2.7% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this,… | |
| Modificada | Alta (7.5) | 2.5% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting… | |
| Modificada | Crítica (9.8) | 0.97% | — | Clusterlabs PCSRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUS | 17/5/2023 | 17/6/2026 | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was… | |
| Modificada | Media (6.7) | 0.20% | — | Linuxfoundation Open Cluster Management | 24/4/2023 | 17/6/2026 | A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account or using the service account to list all… | |
| Modificada | Alta (8.8) | 0.19% | — | Clusternet | 24/4/2023 | 17/6/2026 | Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in clusternet prior to version 0.15.2 can be leveraged to lead to a cluster-level privilege escalation. The clusternet has a deployment called `cluster-hub` inside the `clusternet-system` Kubernetes… | |
| Modificada | Media (5.5) | 1.3% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the… | |
| Modificada | Media (5.9) | 1.9% | — | Haxx LibcurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapBroadcom Brocade Fabric Operating System Firmware+5 | 30/3/2023 | 17/6/2026 | A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads… | |
| Modificada | Alta (8.8) | 2.0% | — | Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+5 | 30/3/2023 | 17/6/2026 | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation… | |
| Modificada | Media (6.5) | 1.7% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp H300s Firmware+5 | 23/2/2023 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain"… | |
| Modificada | Media (6.5) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is… | |
| Modificada | Crítica (9.1) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL.… | |
| Modificada | Media (6.3) | 0.60% | — | Oracle Mysql Cluster | 18/1/2023 | 17/6/2026 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected are 7.4.38 and prior, 7.5.28 and prior, 7.6.24 and prior and 8.0.31 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical… | |
| Modificada | Alta (7.8) | 0.23% | — | Redhat Advanced Cluster Management FOR Kubernetes | 13/1/2023 | 17/6/2026 | RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check,… | |
| Modificada | Media (6.5) | 1.9% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+4 | 5/12/2022 | 17/6/2026 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or… | |
| Modificada | Crítica (9.8) | 4.7% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+5 | 5/12/2022 | 17/6/2026 | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and… | |
| Modificada | Alta (7.8) | 5.8% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. | |
| Modificada | Alta (7.5) | 41% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. | |
| Modificada | Media (4.3) | 0.57% | — | Jenkins Cluster Statistics | 15/11/2022 | 17/6/2026 | A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics. | |
| Modificada | Media (4.3) | 0.39% | — | Jenkins Cluster Statistics | 15/11/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics. |