Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

583 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)3.2%—PythonDebian LinuxRedhat Software CollectionsRedhat Enterprise Linux+124/8/202217/6/2026
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given…
ModificadaAlta (7.8)0.75%—GNU GlibcDebian LinuxNetapp E-series Performance AnalyzerNetapp NFS Plug-in+624/8/202217/6/2026
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and…
ModificadaAlta (7.5)1.8%—GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp H300s FirmwareNetapp H500s Firmware+324/8/202217/6/2026
A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
ModificadaAlta (7.8)0.54%—Vmware ToolsDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility23/8/202217/6/2026
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
ModificadaMedia (6.5)1.5%💥 PoCRedhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+1023/8/202217/6/2026
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged…
ModificadaCrítica (9.8)19%💥 PoCZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+145/8/202214/7/2026
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the…
ModificadaAlta (7.5)23%💥 PoCSqliteNetapp Ontap Select Deploy Administration UtilitySplunk Universal Forwarder3/8/202217/6/2026
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
ModificadaMedia (6.5)0.66%—IBM Urbancode Deploy1/8/202217/6/2026
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. IBM X-Force ID: 231360.
ModificadaMedia (6.5)1.9%—LibtiffFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+129/7/202217/6/2026
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
ModificadaMedia (6.5)0.78%—Jenkins Openshift Deployer27/7/202217/6/2026
A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an…
ModificadaMedia (6.5)0.53%—Jenkins Openshift Deployer27/7/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.
ModificadaMedia (6.5)0.76%—Jenkins Openshift Deployer27/7/202217/6/2026
A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
ModificadaMedia (6.5)0.53%—Jenkins Openshift Deployer27/7/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.
ModificadaMedia (4.3)0.56%—Jenkins Deployer Framework27/7/202217/6/2026
A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/Read permission but without Deploy Now/Deploy permission to read deployment logs.
ModificadaMedia (4.3)1.2%—Jenkins Deployer Framework27/7/202217/6/2026
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
ModificadaAlta (8.8)1.7%—Jenkins Deployer Framework27/7/202217/6/2026
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.
ModificadaMedia (4.5)0.47%—GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+96/7/202217/6/2026
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman…
ModificadaMedia (4.5)0.46%—GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+106/7/202217/6/2026
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform…
ModificadaMedia (6.5)2.8%—GnupgFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+11/7/202217/6/2026
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
ModificadaMedia (5.5)0.15%—IBM Urbancode Deploy1/7/202217/6/2026
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
ModificadaMedia (4.4)0.43%—IBM Urbancode Deploy1/7/202217/6/2026
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 22106.
ModificadaMedia (4.3)0.59%—Jenkins Deployment Dashboard30/6/202217/6/2026
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (4.3)0.57%—Jenkins Deployment Dashboard30/6/202217/6/2026
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.
ModificadaMedia (4.3)0.59%—Jenkins Deployment Dashboard30/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials.
ModificadaMedia (4.3)0.72%—Jenkins Deployment Dashboard30/6/202217/6/2026
A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Orbitaley — Vulnerabilidades