Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.26% | — | Linux KernelDebian LinuxNetapp A1K FirmwareNetapp A70 Firmware+25 | 3/4/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is… | |
| Analizada | Media (6.5) | 1.3% | — | Haxx CurlApple MacosNetapp H700s FirmwareNetapp Bootstrap OS+3 | 27/3/2024 | 17/6/2026 | libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all… | |
| Analizada | Alta (8.6) | 36% | — | Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+10 | 27/3/2024 | 17/6/2026 | When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.… | |
| Analizada | Media (6.3) | 1.7% | — | Haxx CurlApple MacosNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+8 | 27/3/2024 | 17/6/2026 | libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems. | |
| Analizada | Baja (3.5) | 1.7% | — | Haxx CurlFedoraproject FedoraApple MacosNetapp Ontap+6 | 27/3/2024 | 17/6/2026 | When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled.… | |
| Analizada | Alta (7.3) | 2.1% | — | Apache Commons ConfigurationFedoraproject FedoraNetapp Ontap ToolsNetapp Snapcenter | 21/3/2024 | 17/6/2026 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | |
| Modificada | Media (5.5) | 0.58% | — | Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+10 | 18/3/2024 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h variable after this call as it can change skb->head. | |
| Analizada | Media (5.5) | 0.33% | — | Linux KernelDebian LinuxNetapp Ontap Select Deploy Administration UtilityNetapp Ontap Tools+16 | 18/3/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim() syzbot pointed out [1] that NEXTHDR_FRAGMENT handling is broken. Reading frag_off can only be done if we pulled enough bytes to skb->head. Currently we might access garbage. | |
| Analizada | Alta (8.1) | 2.6% | — | Vmware Spring FrameworkNetapp Active IQ Unified Manager | 16/3/2024 | 17/6/2026 | Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is… | |
| Analizada | Crítica (9.3) | 2.5% | 💥 PoC | Apache CXFNetapp Oncommand Workflow AutomationNetapp Ontap Tools | 15/3/2024 | 17/6/2026 | A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted. | |
| Modificada | Alta (7.5) | 2.0% | 💥 PoC | Libexpat Project LibexpatFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+10 | 10/3/2024 | 17/6/2026 | libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). | |
| Analizada | Crítica (9.8) | 0.50% | — | MongodbNetapp Astra Control CenterNetapp Ontap Tools | 7/3/2024 | 17/6/2026 | Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate… | |
| Modificada | Alta (7.5) | 65% | — | Squid-cache SquidFedoraproject FedoraNetapp Bluexp | 6/3/2024 | 17/6/2026 | Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP… | |
| Modificada | Media (5.5) | 0.28% | — | Linux KernelDebian LinuxNetapp H610c FirmwareNetapp H610s Firmware+1 | 6/3/2024 | 15/8/2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper() Return invalid error code -EINVAL for invalid block id. Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c:1183 amdgpu_ras_query_error_status_helper() error: we… | |
| Modificada | Media (5.5) | 0.44% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+4 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. | |
| Analizada | Alta (7.5) | 1.1% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+5 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. | |
| Analizada | Media (5.3) | 0.81% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+5 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. | |
| Modificada | Alta (7.5) | 1.4% | — | Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp Bluexp | 26/2/2024 | 17/6/2026 | Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new… | |
| Analizada | Media (5.4) | 0.63% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267451. | |
| Analizada | Media (6.1) | 0.69% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260744. | |
| Analizada | Media (4.3) | 0.38% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an arbitrary path. IBM X-Force ID: 255898. | |
| Analizada | Media (5.3) | 0.42% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290. | |
| Analizada | Media (6.5) | 1.2% | — | Netapp Oncommand InsightIBM Cognos Analytics | 26/2/2024 | 17/6/2026 | IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users.… | |
| Modificada | Alta (7.8) | 0.25% | — | Netapp Ontap ToolsLinux Kernel | 20/2/2024 | 4/8/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends. Skip sync GC for such elements otherwise commit path might walk over an already released object.… | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Nodejs Node.jsNetapp Astra Control Center | 20/2/2024 | 17/6/2026 | A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The… |