Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.97% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+5 | 25/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The… | |
| Modificada | Alta (7) | 0.31% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+11 | 18/1/2022 | 17/6/2026 | A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This… | |
| Modificada | Alta (7.8) | 1.9% | 💥 PoC | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+7 | 14/1/2022 | 17/6/2026 | kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. | |
| Analizada | Alta (7.5) | 3.6% | 💥 PoC | Linux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+22 | 25/12/2021 | 5/8/2026 | In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses. | |
| Modificada | Alta (7.8) | 0.55% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware+7 | 23/12/2021 | 17/6/2026 | In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry. | |
| Analizada | Alta (7) | 0.71% | 💥 PoC | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux+8 | 22/12/2021 | 5/8/2026 | A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. | |
| Modificada | Alta (7.5) | 0.88% | — | Ksmbd Project KsmbdNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+5 | 16/12/2021 | 17/6/2026 | The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. When… | |
| Modificada | Alta (7.5) | 50% | 💥 PoC | OpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+12 | 14/12/2021 | 17/6/2026 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as… | |
| Modificada | Alta (7.8) | 0.52% | — | Linux KernelNetapp Cloud BackupNetapp H410c FirmwareNetapp H300s Firmware+6 | 8/12/2021 | 17/6/2026 | The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c. | |
| Modificada | Media (4.6) | 0.69% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+11 | 17/11/2021 | 17/6/2026 | In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). | |
| Modificada | Media (6.7) | 0.55% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+7 | 17/11/2021 | 17/6/2026 | In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value. | |
| Modificada | Alta (7.5) | 3.7% | — | Gmplib GMPDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+4 | 15/11/2021 | 17/6/2026 | GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms. | |
| Modificada | Alta (7.8) | 0.49% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+5 | 28/10/2021 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate privileges, aka CID-a3727a8bac0a. This occurs because of an attempt to access the subjective… | |
| Modificada | Media (5.3) | 11% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp H300s Firmware+11 | 27/10/2021 | 17/6/2026 | In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause… | |
| Modificada | Media (6.1) | 41% | 💥 PoC | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+23 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A… | |
| Modificada | Media (6.1) | 8.5% | — | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+24 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as… | |
| Modificada | Media (6.1) | 39% | 💥 PoC | Jqueryui Jquery UIFedoraproject FedoraNetapp H500s FirmwareNetapp H700s Firmware+25 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS… | |
| Modificada | Media (6.7) | 0.87% | 💥 PoC | Linux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+6 | 21/10/2021 | 17/6/2026 | dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within parse_write_buffer_into_params when it… | |
| Analizada | Alta (7.8) | 0.37% | — | Netapp Cloud BackupLinux KernelNetapp H300s FirmwareNetapp H500s Firmware+7 | 11/10/2021 | 5/8/2026 | An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain… | |
| Modificada | Alta (7.8) | 1.6% | 💥 PoC | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+7 | 5/10/2021 | 17/6/2026 | The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access. | |
| Analizada | Alta (7.8) | 0.41% | — | Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp HCI Management Node+11 | 2/10/2021 | 5/8/2026 | prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write. | |
| Modificada | Alta (7.8) | 0.58% | — | Linux KernelNetapp Cloud BackupNetapp H410c FirmwareNetapp H300s Firmware+7 | 20/9/2021 | 17/6/2026 | arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed the 128 KB limit of the MIPS architecture. | |
| Modificada | Alta (7.8) | 1.8% | 💥 PoC | Linux KernelDebian LinuxFedoraproject FedoraNetapp Cloud Backup+9 | 19/9/2021 | 17/6/2026 | loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation. | |
| Analizada | Alta (7) | 0.31% | — | Netapp Solidfire Baseboard Management ControllerLinux KernelFedoraproject FedoraDebian Linux+13 | 3/9/2021 | 13/8/2026 | A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13. | |
| Modificada | Media (6.5) | 2.0% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesOracle ZFS Storage Appliance KITNetapp Active IQ Unified Manager+15 | 9/7/2021 | 17/6/2026 | A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |