Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

583 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.64%—Jenkins Deployment Dashboard30/6/202217/6/2026
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.
ModificadaMedia (5.4)0.80%—Jenkins CRX Content Package Deployer23/6/202217/6/2026
Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaAlta (7.3)95%—OpensslDebian LinuxFedoraproject FedoraSiemens Sinec INS+2421/6/202217/6/2026
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in…
ModificadaAlta (7.5)3.9%—Npmjs NPMNetapp Ontap Select Deploy Administration Utility13/6/202217/6/2026
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files…
ModificadaAlta (7.5)0.89%—Octopus Deploy13/6/202217/6/2026
In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space.
ModificadaCrítica (9.8)3.2%—Debian DpkgDebian LinuxNetapp Ontap Select Deploy Administration Utility26/5/202217/6/2026
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory…
ModificadaCrítica (9.1)2.8%—Pcre2Redhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+816/5/202217/6/2026
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
AnalizadaCrítica (9.1)3.4%—Pcre2Fedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+916/5/202217/6/2026
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching…
ModificadaAlta (7.8)0.23%—Acronis Snap Deploy16/5/202217/6/2026
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640
ModificadaAlta (7.8)0.25%—Acronis Snap Deploy16/5/202217/6/2026
Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640
ModificadaAlta (7.8)0.20%—Acronis Snap Deploy16/5/202217/6/2026
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640
ModificadaMedia (5.5)1.3%—LibtiffFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityDebian Linux11/5/202217/6/2026
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
ModificadaMedia (5.5)1.7%—LibtiffFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityApple Iphone OS+311/5/202217/6/2026
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
ModificadaMedia (6.5)3.8%—Xmlsoft Libxml2Xmlsoft LibxsltFedoraproject FedoraDebian Linux+153/5/202217/6/2026
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for…
ModificadaAlta (7.5)4.9%—AngularjsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility1/5/202217/6/2026
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no…
ModificadaAlta (7.5)0.66%—IBM Urbancode Deploy29/4/202217/6/2026
IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
ModificadaAlta (8.8)0.75%—IBM Urbancode Deploy27/4/202217/6/2026
IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.
ModificadaAlta (7.6)7.1%💥 PoCPythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityNetapp Snapcenter+113/4/202217/6/2026
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or…
ModificadaMedia (6.5)1.9%—LibtiffNetapp Ontap Select Deploy Administration Utility3/4/202217/6/2026
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.5)0.72%—IBM Urbancode Deploy1/4/202217/6/2026
IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859.
ModificadaMedia (4.3)1.0%—Redhat LibvirtNetapp Ontap Select Deploy Administration Utility25/3/202217/6/2026
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a…
ModificadaMedia (6.5)0.24%—Redhat LibvirtFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility25/3/202217/6/2026
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
ModificadaMedia (5.3)0.92%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment25/3/202217/6/2026
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps.
ModificadaAlta (7.5)52%💥 PoCNokogiriPythonZlibDebian Linux+2325/3/202214/7/2026
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
ModificadaMedia (6.5)0.92%—Jenkins Kubernetes Continuous Deploy15/3/202217/6/2026
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.