Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

382 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.50%—Linux KernelNetapp Solidfire Baseboard Management Controller FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+187/6/202117/6/2026
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
ModificadaMedia (5.5)5.4%—GstreamerNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+82/6/202117/6/2026
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
ModificadaAlta (7.8)0.38%—Linux KernelFedoraproject FedoraNetapp Cloud BackupNetapp Solidfire & HCI Management Node+827/5/202117/6/2026
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off…
ModificadaAlta (7.4)6.1%—ISC DhcpFedoraproject FedoraDebian LinuxSiemens Ruggedcom ROX Rx1400 Firmware+1226/5/202117/6/2026
In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those…
ModificadaAlta (7.8)0.63%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management Node+926/5/202117/6/2026
A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there is still an alias in sunkbd_reinit causing Use After Free.
ModificadaAlta (7)1.0%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management Node+1126/5/202117/6/2026
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
ModificadaAlta (8.7)0.66%—Linux KernelFedoraproject FedoraDebian LinuxNetapp H410c Firmware+926/5/202117/6/2026
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local…
ModificadaMedia (5.5)0.47%—Linux KernelFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+926/5/202117/6/2026
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.
ModificadaAlta (7.8)0.51%—Linux KernelFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+1026/5/202117/6/2026
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
ModificadaAlta (7.8)0.59%—Linux KernelFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+1026/5/202117/6/2026
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
ModificadaCrítica (9.8)2.9%—GNU GlibcFedoraproject FedoraNetapp Cloud BackupNetapp E-series Santricity OS Controller+925/5/202117/6/2026
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified…
ModificadaAlta (7.5)3.1%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+1025/5/202117/6/2026
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
ModificadaAlta (7)1.8%💥 PoCLinux KernelNetapp Solidfire Baseboard Management Controller FirmwareNetapp Cloud BackupNetapp H500s Firmware+621/5/202117/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The…
ModificadaAlta (8.6)17%—Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+2419/5/202117/6/2026
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application…
ModificadaAlta (7.8)0.65%—Linux KernelNetapp Cloud BackupNetapp Solidfire & HCI Management NodeNetapp Solidfire Baseboard Management Controller Firmware+814/5/202117/6/2026
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.
AnalizadaAlta (7.8)0.38%—Netapp Cloud BackupNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+612/5/202130/7/2026
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
ModificadaAlta (7)0.69%💥 PoCLinux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+710/5/202117/6/2026
net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
ModificadaAlta (7.8)0.41%—Linux KernelNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller FirmwareNetapp H300s Firmware+76/5/202117/6/2026
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The…
ModificadaAlta (7.1)0.38%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+156/5/20215/8/2026
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
ModificadaMedia (5.3)3.6%—Oracle JDKOracle JREDebian LinuxFedoraproject Fedora+722/4/202117/6/2026
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to…
ModificadaMedia (5.9)3.5%—Oracle JDKOracle JREDebian LinuxFedoraproject Fedora+822/4/202117/6/2026
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to…
AnalizadaAlta (7)0.47%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1122/4/202130/7/2026
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list…
AnalizadaAlta (7.1)0.37%—Linux KernelDebian LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware+819/4/20211/9/2026
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from…
ModificadaAlta (7.8)0.93%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+98/4/202117/6/2026
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.
ModificadaBaja (3.7)3.1%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+71/4/202117/6/2026
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server…