Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.63% | — | Golang GO | 10/8/2022 | 17/6/2026 | Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset. | |
| Modificada | Alta (7.5) | 2.3% | — | Golang GO | 10/8/2022 | 17/6/2026 | Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. | |
| Modificada | Alta (7.5) | 2.4% | — | Golang GOFedoraproject FedoraNetapp Cloud Insights Telegraf | 10/8/2022 | 17/6/2026 | Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document. | |
| Modificada | Media (5.5) | 0.92% | — | Golang GO | 10/8/2022 | 17/6/2026 | Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations. | |
| Modificada | Media (6.5) | 1.4% | — | Golang GO | 10/8/2022 | 17/6/2026 | Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid. | |
| Modificada | Alta (7.5) | 2.3% | — | Golang GONetapp Cloud Insights Telegraf Agent | 15/7/2022 | 17/6/2026 | Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes. | |
| Modificada | Media (5.3) | 3.0% | — | Golang GOFedoraproject FedoraNetapp Beegfs CSI Driver | 23/6/2022 | 17/6/2026 | Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible. | |
| Modificada | Alta (7.5) | 4.2% | — | Golang GOFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 20/4/2022 | 17/6/2026 | The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input. | |
| Modificada | Alta (7.5) | 1.5% | — | Golang GO | 20/4/2022 | 17/6/2026 | Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic. | |
| Modificada | Alta (7.5) | 10.0% | 💥 PoC | Golang GOFedoraproject FedoraNetapp Kubernetes Monitoring Operator | 20/4/2022 | 17/6/2026 | encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data. | |
| Modificada | Alta (7.5) | 3.9% | — | Golang SSHFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Advanced Cluster Management FOR Kubernetes | 18/3/2022 | 17/6/2026 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | |
| Modificada | Alta (7.5) | 3.2% | — | Golang GONetapp Astra TridentDebian Linux | 5/3/2022 | 17/6/2026 | regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. | |
| Modificada | Alta (7.5) | 6.0% | — | Prometheus Client GolangFedoraproject FedoraFedoraproject Extra Packages FOR Enterprise LinuxRDO Project RDO | 15/2/2022 | 17/6/2026 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory… | |
| Modificada | Crítica (9.1) | 3.1% | — | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+2 | 11/2/2022 | 17/6/2026 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. | |
| Modificada | Alta (7.5) | 2.7% | 💥 PoC | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+1 | 11/2/2022 | 17/6/2026 | cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags. | |
| Modificada | Alta (7.5) | 2.8% | — | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+2 | 11/2/2022 | 17/6/2026 | Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. | |
| Modificada | Alta (7.5) | 6.9% | — | Golang GONetapp Cloud Insights Telegraf | 24/1/2022 | 17/6/2026 | In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196. | |
| Modificada | Media (4.8) | 1.9% | — | Golang GODebian Linux | 1/1/2022 | 17/6/2026 | Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion. | |
| Modificada | Alta (7.5) | 4.0% | — | Golang GODebian LinuxNetapp Cloud Insights Telegraf | 1/1/2022 | 17/6/2026 | net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests. | |
| Modificada | Alta (7.5) | 3.3% | — | Golang GOFedoraproject FedoraOracle Timesten In-memory Database | 8/11/2021 | 17/6/2026 | Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. | |
| Modificada | Alta (7.5) | 4.7% | — | Golang GOFedoraproject FedoraDebian Linux | 8/11/2021 | 17/6/2026 | ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation. | |
| Modificada | Crítica (9.8) | 11% | 💥 PoC | Golang GOFedoraproject Fedora | 18/10/2021 | 17/6/2026 | Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used. | |
| Modificada | Media (6.5) | 0.43% | — | In-toto-golang | 21/9/2021 | 17/6/2026 | in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout. An… | |
| Modificada | Media (5.9) | 3.1% | — | Golang GOFedoraproject FedoraDebian LinuxOracle Timesten In-memory Database+1 | 8/8/2021 | 17/6/2026 | Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort. | |
| Modificada | Alta (7.5) | 3.7% | — | Golang GOOracle Timesten In-memory DatabaseFedoraproject Fedora | 7/8/2021 | 17/6/2026 | Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR. |