Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Alta (7.5) | 2.1% | — | Schema-inspector Project Schema-inspectorNetapp E-series Performance AnalyzerNetapp Oncommand Insight | 19/3/2021 | 17/6/2026 | Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example… | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | GrafanaNetapp E-series Performance Analyzer | 18/3/2021 | 17/6/2026 | The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set. | |
| Modificada | Alta (7.5) | 1.1% | — | Spdk Storage Performance Development KIT | 13/3/2021 | 17/6/2026 | An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with a NULL pointer dereference. | |
| Modificada | Crítica (9.8) | 3.8% | — | GnutlsRedhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+1 | 12/3/2021 | 17/6/2026 | A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences. | |
| Modificada | Alta (7.5) | 37% | — | Nodejs Node.jsFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+9 | 3/3/2021 | 17/6/2026 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof… | |
| Modificada | Alta (7.5) | 77% | — | Nodejs Node.jsFedoraproject FedoraNetapp E-series Performance AnalyzerOracle Graalvm+5 | 3/3/2021 | 17/6/2026 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new… | |
| Modificada | Baja (3.3) | 0.30% | — | IBM Cloud Application Performance Management | 2/3/2021 | 17/6/2026 | The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975. | |
| Modificada | Baja (3.5) | 0.73% | — | IBM Cloud Application Performance Management | 2/3/2021 | 17/6/2026 | IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user. IBM X-Force ID: 187974. | |
| Modificada | Media (4.9) | 0.92% | — | IBM Cloud Application Performance Management | 2/3/2021 | 17/6/2026 | The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861. | |
| Modificada | Alta (7.5) | 3.0% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption. | |
| Modificada | Alta (7.5) | 4.1% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation. | |
| Modificada | Alta (8.8) | 5.3% | — | Solarwinds Network Performance Monitor | 12/2/2021 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The specific flaw exists within the WriteToFile method. The issue results from the lack of proper… | |
| Modificada | Media (6.5) | 0.48% | — | Microfocus Application Performance Management | 6/2/2021 | 17/6/2026 | Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing. | |
| Modificada | Media (4.8) | 0.61% | — | Microfocus Application Performance Management | 6/2/2021 | 17/6/2026 | Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack. | |
| Modificada | Media (6.5) | 0.67% | — | Hcltechsw Onetest Performance | 4/2/2021 | 17/6/2026 | HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID. | |
| Modificada | Alta (7.5) | 0.69% | — | Hcltechsw Onetest Performance | 4/2/2021 | 17/6/2026 | HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials. | |
| Modificada | Crítica (9.8) | 1.2% | — | Hcltechsw Onetest Performance | 4/2/2021 | 17/6/2026 | HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources. | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+20 | 26/1/2021 | 17/6/2026 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| Modificada | Media (4.8) | 0.59% | — | Employee Performance Evaluation System Project Employee Performance Evaluation System | 20/1/2021 | 17/6/2026 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields. | |
| Modificada | Media (4.8) | 0.55% | — | Employee Performance Evaluation System Project Employee Performance Evaluation System | 20/1/2021 | 17/6/2026 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields. | |
| Modificada | Media (4.4) | 0.24% | — | SAP Enterprise Performance Management | 12/1/2021 | 17/6/2026 | SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-based attacks in applications that accept attacker-controlled XML configuration files. This occurs… | |
| Modificada | Media (5.4) | 1.4% | — | Solarwinds Database Performance Analyzer | 15/12/2020 | 17/6/2026 | SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen. | |
| Modificada | Alta (7.8) | 0.67% | — | Passmark BurnintestPassmark OsforensicsPassmark Performancetest | 13/11/2020 | 17/6/2026 | An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling process. This could lead to arbitrary… | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Microfocus Application Performance ManagementMicrofocus Operations BridgeMicrofocus Operations Bridge Manager | 27/10/2020 | 17/6/2026 | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.)… |