Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.26% | — | Intel Xeon Gold 5315y FirmwareIntel Xeon Gold 5317 FirmwareIntel Xeon Gold 5318n FirmwareIntel Xeon Gold 5318s Firmware+68 | 18/8/2022 | 17/6/2026 | Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.32% | — | Linux KernelDebian LinuxNetapp A700s FirmwareNetapp Active IQ Unified Manager+20 | 27/7/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. | |
| Modificada | Alta (7) | 2.5% | — | Openbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+8 | 26/9/2021 | 14/7/2026 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of… | |
| Analizada | Alta (7) | 0.30% | — | Netapp Solidfire Baseboard Management ControllerLinux KernelFedoraproject FedoraDebian Linux+13 | 3/9/2021 | 13/8/2026 | A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13. | |
| Analizada | Alta (7.8) | 79% | ⚠ Explotación activa | Netapp C400 FirmwareNetapp C250 FirmwareNetapp H410c FirmwareNetapp H300s Firmware+17 | 7/7/2021 | 17/6/2026 | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space | |
| Modificada | Alta (7.8) | 0.79% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+8 | 26/5/2021 | 17/6/2026 | A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | |
| Modificada | Crítica (9.8) | 82% | — | Debian LinuxISC BindSiemens Sinec Infrastructure Network ServicesNetapp Active IQ Unified Manager+10 | 29/4/2021 | 17/6/2026 | In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured… | |
| Modificada | Media (6.5) | 6.0% | — | ISC BindDebian LinuxFedoraproject FedoraSiemens Sinec Infrastructure Network Services+11 | 29/4/2021 | 17/6/2026 | In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR… | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+3 | 22/3/2021 | 17/6/2026 | In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6. | |
| Modificada | Media (4.7) | 0.27% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+3 | 22/3/2021 | 17/6/2026 | A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc. | |
| Modificada | Media (5.9) | 7.1% | — | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… |