Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—Netapp Oncommand Unified Manager Core Package26/5/201717/6/2026
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaCrítica (9.8)7.5%—ZlibOpensuse LeapOpensuseDebian Linux+3523/5/201714/7/2026
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
ModificadaCrítica (9.8)2.9%—Netapp Oncommand Unified Manager FOR Clustered Data Ontap7/2/201717/6/2026
NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.1)2.8%—Littlecms Little CMS Color EngineCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+153/2/201717/6/2026
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
ModificadaMedia (5.3)15%—NTPDebian LinuxNetapp Clustered Data OntapNetapp Data Ontap+1330/1/201717/6/2026
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
AnalizadaAlta (7.5)6.1%—Netapp Clustered Data OntapNetapp Data Ontap Operating IN 7-modeNetapp Oncommand BalanceNetapp Oncommand Performance Manager+26/1/201717/6/2026
An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash.
AnalizadaAlta (7)84%⚠ Explotación activa💥 ExploitCanonical Ubuntu LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1410/11/201617/6/2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
AnalizadaCrítica (9.8)92%⚠ Explotación activaOracle JDKOracle JREOracle JrockitOracle Linux+3421/4/201617/6/2026
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
AnalizadaAlta (8.8)83%⚠ Explotación activa💥 ExploitRedhat Jboss Enterprise Application PlatformNetapp Oncommand BalanceNetapp Oncommand InsightNetapp Oncommand Unified Manager5/8/201016/6/2026
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security…