Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

566 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—NEC Expresscluster XNEC Expresscluster X Singleserversafe8/11/202217/6/2026
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on…
ModificadaCrítica (9.8)1.2%—NEC Expresscluster XNEC Expresscluster X Singleserversafe8/11/202217/6/2026
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite…
ModificadaCrítica (9.8)1.4%—NEC Expresscluster XNEC Expresscluster X Singleserversafe8/11/202217/6/2026
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the…
ModificadaCrítica (9.8)1.5%—NEC Expresscluster XNEC Expresscluster X Singleserversafe8/11/202217/6/2026
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the…
ModificadaAlta (7.5)91%💥 PoCOpensslFedoraproject FedoraNetapp Clustered Data OntapNodejs Node.js1/11/202217/6/2026
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite…
ModificadaAlta (8.1)0.75%—Netapp Clustered Data Ontap19/10/202217/6/2026
Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period.
ModificadaBaja (3.7)2.4%—Haxx CurlNetapp Clustered Data OntapNetapp Element SoftwareNetapp HCI Management Node+923/9/202217/6/2026
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
ModificadaAlta (7.8)0.32%—Clusterlabs PCSDebian Linux6/9/202217/6/2026
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to…
ModificadaMedia (6.5)0.92%—Redhat Advanced Cluster Management FOR Kubernetes1/9/202217/6/2026
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability…
ModificadaAlta (8.8)1.4%—Redhat Advanced Cluster Security1/9/202217/6/2026
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
ModificadaAlta (8.8)1.2%—Clusterlabs Hawk26/8/202217/6/2026
An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid program. This allows the hacluster user to invoke certain commands as root (with an attempt to limit this to safe combinations). This user…
ModificadaMedia (6.5)1.3%—Clusterlabs BoothDebian LinuxFedoraproject Fedora28/7/202217/6/2026
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
ModificadaMedia (6.3)51%—Oracle Mysql ClusterNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+119/7/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.36 and prior, 7.5.26 and prior, 7.6.22 and prior and and 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication…
ModificadaMedia (5.9)1.4%—Oracle Mysql ClusterNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+119/7/202217/6/2026
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this…
ModificadaMedia (5.9)7.5%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+107/7/202217/6/2026
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
ModificadaCrítica (9.8)7.7%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+107/7/202217/6/2026
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file…
ModificadaMedia (6.5)33%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+157/7/202217/6/2026
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of…
ModificadaMedia (4.3)28%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+157/7/202217/6/2026
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold…
ModificadaMedia (5.3)4.9%💥 PoCOpensslFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap Antivirus Connector+75/7/202217/6/2026
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the…
AnalizadaCrítica (9.8)3.5%💥 PoCApache Http ServerNetapp Clustered Data OntapFedoraproject Fedora9/6/202217/6/2026
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
AnalizadaAlta (7.5)5.3%—Apache Http ServerNetapp Clustered Data OntapFedoraproject Fedora9/6/202217/6/2026
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
ModificadaAlta (7.5)90%—Apache Http ServerNetapp Clustered Data OntapFedoraproject Fedora9/6/202217/6/2026
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.
ModificadaAlta (7.5)6.4%—Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap9/6/202217/6/2026
In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
ModificadaCrítica (9.1)6.3%—Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap9/6/202217/6/2026
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may…
ModificadaMedia (5.3)5.0%—Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap9/6/202217/6/2026
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the…
Orbitaley — Vulnerabilidades