Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

319 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.2%—ISC BindNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+219/5/202217/6/2026
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations…
AnalizadaAlta (7)0.53%—Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+618/5/202226/8/2026
A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.
ModificadaAlta (7.8)0.93%💥 PoCLinux KernelDebian LinuxCanonical Ubuntu LinuxNetapp H300s Firmware+717/5/202217/6/2026
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
ModificadaAlta (7.8)0.51%—Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+117/5/202217/6/2026
Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.
ModificadaCrítica (9.1)2.8%—Pcre2Redhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+816/5/202217/6/2026
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
AnalizadaCrítica (9.1)3.4%—Pcre2Fedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+916/5/202217/6/2026
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching…
ModificadaAlta (7.8)0.81%💥 PoCLinux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+616/5/202217/6/2026
A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.
ModificadaAlta (7.8)0.80%💥 PoCLinux KernelDebian LinuxNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+912/5/202217/6/2026
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
ModificadaCrítica (9.8)64%—OpenldapDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+44/5/202217/6/2026
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
ModificadaAlta (7.5)2.5%—OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+223/5/202217/6/2026
The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without…
ModificadaMedia (5.9)1.1%—OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+223/5/202217/6/2026
The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the…
ModificadaMedia (5.3)1.2%—OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+223/5/202217/6/2026
The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that…
ModificadaAlta (7.3)83%💥 PoCSiemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+313/5/202217/6/2026
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the…
ModificadaMedia (6.5)3.8%—Xmlsoft Libxml2Xmlsoft LibxsltFedoraproject FedoraDebian Linux+153/5/202217/6/2026
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for…
AnalizadaAlta (7.8)1.1%💥 PoCLinux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+42/5/20222/10/2026
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
ModificadaAlta (7.1)0.40%—Linux KernelDebian LinuxRedhat Enterprise LinuxNetapp H300s Firmware+729/4/20225/8/2026
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
ModificadaAlta (7)0.24%—Linux KernelRedhat Enterprise LinuxDebian LinuxNetapp H300s Firmware+729/4/202217/6/2026
A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.
ModificadaAlta (7.8)0.38%—Linux KernelNetapp H300e FirmwareNetapp H300s FirmwareNetapp H410c Firmware+513/4/202217/6/2026
drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.
ModificadaAlta (7.8)0.41%—Linux KernelNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management NodeNetapp HCI Compute Node Firmware+911/4/202217/6/2026
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
ModificadaAlta (7)0.33%—Linux KernelRedhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+118/4/202217/6/2026
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
ModificadaMedia (5.5)0.32%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+73/4/202217/6/2026
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
ModificadaMedia (5.5)0.40%—Linux KernelDebian LinuxFedoraproject FedoraNetapp H300s Firmware+73/4/202217/6/2026
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
ModificadaAlta (7.8)0.37%—Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+530/3/202217/6/2026
An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
AnalizadaAlta (8.6)0.50%—Linux KernelRedhat Enterprise LinuxFedoraproject FedoraCanonical Ubuntu Linux+829/3/202213/8/2026
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
AnalizadaAlta (7.8)8.8%⚠ Explotación activa💥 ExploitLinux KernelFedoraproject FedoraNetapp H300e FirmwareNetapp H300s Firmware+925/3/202227/8/2026
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.