Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

518 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.6%💥 PoCLibexpat Project LibexpatNetapp Clustered Data OntapNetapp Oncommand Workflow AutomationTenable Nessus+324/1/202217/6/2026
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
ModificadaMedia (5.5)1.3%—LibtiffDebian LinuxNetapp Ontap Select Deploy Administration Utility10/1/202217/6/2026
LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.
ModificadaAlta (7.8)3.8%💥 PoCLibexpat Project LibexpatNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Baseboard Management Controller+46/1/202217/6/2026
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
ModificadaAlta (7.8)1.3%—GNU BinutilsFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+115/12/202117/6/2026
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
ModificadaAlta (7.5)50%💥 PoCOpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+1214/12/202117/6/2026
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as…
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaMedia (5.3)26%💥 PoCPHPNetapp Clustered Data OntapDebian LinuxTenable.sc29/11/202117/6/2026
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus…
ModificadaAlta (7.5)1.3%—Netapp Ontap System Manager1/11/202117/6/2026
Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerability which could allow a remote attacker to cause a crash of the httpd server.
ModificadaMedia (5.5)0.22%—Netapp Ontap System Manager1/11/202117/6/2026
System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow a local attacker to discover plaintext iSCSI CHAP credentials.
ModificadaAlta (7)1.4%—PHPDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+125/10/202117/6/2026
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and…
ModificadaMedia (5.5)0.26%—Netapp Clustered Data Ontap19/10/202117/6/2026
Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the retention period.
ModificadaMedia (6.5)2.1%—SambaDebian LinuxNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+112/10/202117/6/2026
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
ModificadaMedia (4.7)0.62%—Netapp Clustered Data Ontap12/10/202117/6/2026
Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.
ModificadaMedia (5.3)2.1%—PHPNetapp Clustered Data OntapOracle Sd-wan Aware4/10/202117/6/2026
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading…
ModificadaMedia (5.9)1.8%—PHPNetapp Clustered Data Ontap4/10/202117/6/2026
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by…
ModificadaMedia (5.9)3.0%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+2229/9/202117/6/2026
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and…
ModificadaAlta (7.5)4.5%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Cloud Backup+2529/9/202117/6/2026
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly…
ModificadaAlta (7)2.5%💥 PoCOpenbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+826/9/202114/7/2026
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of…
ModificadaCrítica (9.1)6.7%—Haxx LibcurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+1323/9/202117/6/2026
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
AnalizadaCrítica (9.8)39%—Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+716/9/202117/6/2026
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
AnalizadaAlta (7.5)63%—Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+916/9/202117/6/2026
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
ModificadaAlta (7.5)65%—Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1416/9/202117/6/2026
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaMedia (5.3)5.3%💥 PoCOpenbsd OpensshNetapp Clustered Data OntapNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+115/9/202117/6/2026
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not…
ModificadaAlta (7.3)1.7%—VIMFedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility15/9/202117/6/2026
vim is vulnerable to Use After Free
Orbitaley — Vulnerabilidades