Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.64% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | |
| Modificada | Media (5.4) | 0.80% | — | Jenkins CRX Content Package Deployer | 23/6/2022 | 17/6/2026 | Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (7.3) | 95% | — | OpensslDebian LinuxFedoraproject FedoraSiemens Sinec INS+24 | 21/6/2022 | 17/6/2026 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in… | |
| Modificada | Alta (7.5) | 3.9% | — | Npmjs NPMNetapp Ontap Select Deploy Administration Utility | 13/6/2022 | 17/6/2026 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files… | |
| Modificada | Alta (7.5) | 0.89% | — | Octopus Deploy | 13/6/2022 | 17/6/2026 | In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space. | |
| Modificada | Crítica (9.8) | 3.2% | — | Debian DpkgDebian LinuxNetapp Ontap Select Deploy Administration Utility | 26/5/2022 | 17/6/2026 | Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory… | |
| Modificada | Crítica (9.1) | 2.8% | — | Pcre2Redhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+8 | 16/5/2022 | 17/6/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers. | |
| Analizada | Crítica (9.1) | 3.4% | — | Pcre2Fedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+9 | 16/5/2022 | 17/6/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching… | |
| Modificada | Alta (7.8) | 0.23% | — | Acronis Snap Deploy | 16/5/2022 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 | |
| Modificada | Alta (7.8) | 0.25% | — | Acronis Snap Deploy | 16/5/2022 | 17/6/2026 | Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 | |
| Modificada | Alta (7.8) | 0.20% | — | Acronis Snap Deploy | 16/5/2022 | 17/6/2026 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 | |
| Modificada | Media (5.5) | 1.3% | — | LibtiffFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityDebian Linux | 11/5/2022 | 17/6/2026 | LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa. | |
| Modificada | Media (5.5) | 1.7% | — | LibtiffFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityApple Iphone OS+3 | 11/5/2022 | 17/6/2026 | LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa. | |
| Modificada | Media (6.5) | 3.8% | — | Xmlsoft Libxml2Xmlsoft LibxsltFedoraproject FedoraDebian Linux+15 | 3/5/2022 | 17/6/2026 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for… | |
| Modificada | Alta (7.5) | 4.9% | — | AngularjsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 1/5/2022 | 17/6/2026 | The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no… | |
| Modificada | Alta (7.5) | 0.66% | — | IBM Urbancode Deploy | 29/4/2022 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Modificada | Alta (8.8) | 0.75% | — | IBM Urbancode Deploy | 27/4/2022 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955. | |
| Modificada | Alta (7.6) | 7.1% | 💥 PoC | PythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityNetapp Snapcenter+1 | 13/4/2022 | 17/6/2026 | In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or… | |
| Modificada | Media (6.5) | 1.9% | — | LibtiffNetapp Ontap Select Deploy Administration Utility | 3/4/2022 | 17/6/2026 | A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.5) | 0.72% | — | IBM Urbancode Deploy | 1/4/2022 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859. | |
| Modificada | Media (4.3) | 1.0% | — | Redhat LibvirtNetapp Ontap Select Deploy Administration Utility | 25/3/2022 | 17/6/2026 | A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a… | |
| Modificada | Media (6.5) | 0.24% | — | Redhat LibvirtFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 25/3/2022 | 17/6/2026 | A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. | |
| Modificada | Media (5.3) | 0.92% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 25/3/2022 | 17/6/2026 | In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps. | |
| Modificada | Alta (7.5) | 52% | 💥 PoC | NokogiriPythonZlibDebian Linux+23 | 25/3/2022 | 14/7/2026 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | |
| Modificada | Media (6.5) | 0.92% | — | Jenkins Kubernetes Continuous Deploy | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. |