Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.7%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage+226/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
ModificadaAlta (7.5)5.8%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage26/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
ModificadaAlta (7.5)3.9%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage26/2/201916/6/2026
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
ModificadaMedia (6.8)21%💥 ExploitOpenbsd OpensshWinscpNetapp Element SoftwareNetapp Ontap Select Deploy+331/1/201917/6/2026
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
ModificadaMedia (6.8)3.8%—Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+1631/1/201917/6/2026
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects…
ModificadaMedia (5.3)3.7%—Openbsd OpensshWinscpNetapp Cloud BackupNetapp Element Software+1810/1/201917/6/2026
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
ModificadaMedia (5.3)3.6%—Openbsd OpensshNetapp Cloud BackupNetapp Data Ontap EdgeNetapp Ontap Select Deploy+228/8/201817/6/2026
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a…
ModificadaAlta (7.5)3.9%—Palletsprojects FlaskNetapp Active IQNetapp Hyper Converged InfrastructureNetapp Ontap Select Deploy Utility20/8/201817/6/2026
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability…
ModificadaMedia (5.3)99%💥 ExploitOpenbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1817/8/201817/6/2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
ModificadaAlta (7.5)40%💥 PoCOpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4113/11/201717/6/2026
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections…
ModificadaAlta (7.5)1.9%—Netapp Ontap Select Deploy Administration Utility1/3/201717/6/2026
The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors.
AnalizadaAlta (7)84%⚠ Explotación activa💥 ExploitCanonical Ubuntu LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1410/11/201617/6/2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Orbitaley — Vulnerabilidades