Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
518 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.6% | 💥 PoC | Libexpat Project LibexpatNetapp Clustered Data OntapNetapp Oncommand Workflow AutomationTenable Nessus+3 | 24/1/2022 | 17/6/2026 | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffDebian LinuxNetapp Ontap Select Deploy Administration Utility | 10/1/2022 | 17/6/2026 | LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field. | |
| Modificada | Alta (7.8) | 3.8% | 💥 PoC | Libexpat Project LibexpatNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Baseboard Management Controller+4 | 6/1/2022 | 17/6/2026 | In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. | |
| Modificada | Alta (7.8) | 1.3% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+1 | 15/12/2021 | 17/6/2026 | stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699. | |
| Modificada | Alta (7.5) | 50% | 💥 PoC | OpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+12 | 14/12/2021 | 17/6/2026 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (5.3) | 26% | 💥 PoC | PHPNetapp Clustered Data OntapDebian LinuxTenable.sc | 29/11/2021 | 17/6/2026 | In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus… | |
| Modificada | Alta (7.5) | 1.3% | — | Netapp Ontap System Manager | 1/11/2021 | 17/6/2026 | Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerability which could allow a remote attacker to cause a crash of the httpd server. | |
| Modificada | Media (5.5) | 0.22% | — | Netapp Ontap System Manager | 1/11/2021 | 17/6/2026 | System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow a local attacker to discover plaintext iSCSI CHAP credentials. | |
| Modificada | Alta (7) | 1.4% | — | PHPDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+1 | 25/10/2021 | 17/6/2026 | In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and… | |
| Modificada | Media (5.5) | 0.26% | — | Netapp Clustered Data Ontap | 19/10/2021 | 17/6/2026 | Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the retention period. | |
| Modificada | Media (6.5) | 2.1% | — | SambaDebian LinuxNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+1 | 12/10/2021 | 17/6/2026 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server. | |
| Modificada | Media (4.7) | 0.62% | — | Netapp Clustered Data Ontap | 12/10/2021 | 17/6/2026 | Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack. | |
| Modificada | Media (5.3) | 2.1% | — | PHPNetapp Clustered Data OntapOracle Sd-wan Aware | 4/10/2021 | 17/6/2026 | In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading… | |
| Modificada | Media (5.9) | 1.8% | — | PHPNetapp Clustered Data Ontap | 4/10/2021 | 17/6/2026 | In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by… | |
| Modificada | Media (5.9) | 3.0% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+22 | 29/9/2021 | 17/6/2026 | When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and… | |
| Modificada | Alta (7.5) | 4.5% | — | Haxx CurlDebian LinuxFedoraproject FedoraNetapp Cloud Backup+25 | 29/9/2021 | 17/6/2026 | A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly… | |
| Modificada | Alta (7) | 2.5% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+8 | 26/9/2021 | 14/7/2026 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of… | |
| Modificada | Crítica (9.1) | 6.7% | — | Haxx LibcurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+13 | 23/9/2021 | 17/6/2026 | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Crítica (9.8) | 39% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+7 | 16/9/2021 | 17/6/2026 | ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Alta (7.5) | 63% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+9 | 16/9/2021 | 17/6/2026 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). | |
| Modificada | Alta (7.5) | 65% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+14 | 16/9/2021 | 17/6/2026 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (5.3) | 5.3% | 💥 PoC | Openbsd OpensshNetapp Clustered Data OntapNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+1 | 15/9/2021 | 17/6/2026 | OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not… | |
| Modificada | Alta (7.3) | 1.7% | — | VIMFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility | 15/9/2021 | 17/6/2026 | vim is vulnerable to Use After Free |