Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.2%—Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+28/8/202117/6/2026
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
AnalizadaAlta (7.8)0.40%—Linux KernelNetapp HCI Bootstrap OSNetapp HCI Management NodeNetapp Solidfire+37/8/202117/6/2026
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation…
AnalizadaBaja (3.3)0.60%—Debian LinuxNetapp Active IQ Unified ManagerNetapp Bootstrap OSNetapp H610c Firmware+41/7/202117/6/2026
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
ModificadaMedia (6.1)1.3%—React-bootstrap-table Project React-bootstrap-table24/6/202117/6/2026
All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.
ModificadaAlta (7.5)4.6%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1314/12/202017/6/2026
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
ModificadaAlta (7.5)9.8%—Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+1814/12/202017/6/2026
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
ModificadaBaja (3.7)3.9%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+1814/12/202017/6/2026
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
ModificadaAlta (7)0.36%—Linux KernelNetapp Cloud BackupNetapp Element SoftwareNetapp HCI Management Node+328/11/202017/6/2026
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
ModificadaMedia (6.1)1.7%—Snapappointments Bootstrap-select30/9/202017/6/2026
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
ModificadaCrítica (9.1)1.1%—Linux4sam At91bootstrap14/9/202017/6/2026
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).
ModificadaMedia (6.8)0.51%—Linux4sam At91bootstrap14/9/202017/6/2026
A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected system.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
ModificadaBaja (3.7)5.3%—Linux KernelOpensuse LeapFedoraproject FedoraDebian Linux+1130/7/202017/6/2026
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
ModificadaMedia (6.5)5.2%—Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2018/5/202017/6/2026
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
ModificadaMedia (5.3)0.40%—Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+2115/5/202017/6/2026
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
ModificadaMedia (5.5)0.52%—Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+209/5/202017/6/2026
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
ModificadaMedia (6.7)0.59%—Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+199/5/202017/6/2026
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.
ModificadaAlta (7)0.40%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1929/4/202017/6/2026
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur.