Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 3/9/2024 | 17/6/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Modificada | Alta (8.1) | 100% | — | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Modificada | Media (6.5) | 90% | — | Openbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+2 | 3/2/2023 | 17/6/2026 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states… | |
| Analizada | Alta (7.8) | 79% | ⚠ Explotación activa | Netapp C400 FirmwareNetapp C250 FirmwareNetapp H410c FirmwareNetapp H300s Firmware+17 | 7/7/2021 | 17/6/2026 | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space | |
| Modificada | Alta (8.8) | 2.2% | — | Tp-link Nc200 FirmwareTp-link Nc210 FirmwareTp-link Nc220 FirmwareTp-link Nc230 Firmware+3 | 17/6/2020 | 17/6/2026 | TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a… | |
| Modificada | Alta (8.8) | 74% | — | Tp-link Nc200 FirmwareTp-link Nc210 FirmwareTp-link Nc220 FirmwareTp-link Nc230 Firmware+3 | 4/5/2020 | 17/6/2026 | Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304. | |
| Modificada | Crítica (9.8) | 14% | — | Tp-link Nc200 FirmwareTp-link Nc210 FirmwareTp-link Nc220 FirmwareTp-link Nc230 Firmware+3 | 4/5/2020 | 17/6/2026 | Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304. | |
| Modificada | Alta (7.5) | 3.8% | — | Tp-link Nc450 FirmwareTp-link Nc260 FirmwareTp-link Nc250 FirmwareTp-link Nc230 Firmware+3 | 1/4/2020 | 17/6/2026 | TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference. | |
| Modificada | Media (5.3) | 1.8% | — | Tp-link Nc450 FirmwareTp-link Nc260 FirmwareTp-link Nc250 FirmwareTp-link Nc230 Firmware+11 | 1/4/2020 | 17/6/2026 | TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855. | |
| Modificada | Media (6.1) | 1.6% | — | Hms-networks Netbiter Ws100 FirmwareHms-networks Netbiter Ws200 FirmwareHms-networks Netbiter Ec150 FirmwareHms-networks Netbiter Ec250 Firmware+4 | 21/3/2019 | 17/6/2026 | HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form. | |
| Modificada | Media (6.5) | 0.95% | — | Tp-link Nc250 Firmware | 2/7/2017 | 17/6/2026 | On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL. |