Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Modificada | Crítica (9.8) | 42% | — | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Modificada | Crítica (9.8) | 2.5% | — | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version… | |
| Modificada | Alta (7.6) | 0.33% | — | Netapp Clustered Data Ontap | 26/1/2024 | 17/6/2026 | ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege. Possible actions include viewing limited… | |
| Modificada | Media (6.5) | 0.37% | — | Netapp Clustered Data Ontap | 12/1/2024 | 17/6/2026 | ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user. | |
| Modificada | Alta (7.5) | 0.64% | — | Netapp Clustered Data Ontap | 12/10/2023 | 17/6/2026 | ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service. | |
| Modificada | Media (6.5) | 2.8% | — | MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+3 | 7/8/2023 | 17/6/2026 | lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count. | |
| Modificada | Alta (7.5) | 0.65% | — | FreebsdNetapp Clustered Data Ontap | 1/8/2023 | 17/6/2026 | A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service. | |
| Modificada | Alta (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 17/7/2023 | 17/6/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modificada | Alta (7.5) | 1.9% | — | OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+7 | 30/5/2023 | 17/6/2026 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. | |
| Modificada | Baja (3.7) | 2.2% | — | Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+5 | 26/5/2023 | 17/6/2026 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which… | |
| Modificada | Media (5.9) | 1.8% | — | Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+6 | 26/5/2023 | 17/6/2026 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private… | |
| Modificada | Media (5.9) | 2.7% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this,… | |
| Modificada | Alta (7.5) | 2.5% | — | Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+4 | 26/5/2023 | 17/6/2026 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting… | |
| Modificada | Media (5.5) | 1.3% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the… | |
| Modificada | Media (5.9) | 1.9% | — | Haxx LibcurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapBroadcom Brocade Fabric Operating System Firmware+5 | 30/3/2023 | 17/6/2026 | A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads… | |
| Modificada | Alta (8.8) | 2.0% | — | Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+5 | 30/3/2023 | 17/6/2026 | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation… | |
| Modificada | Media (6.5) | 1.7% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp H300s Firmware+5 | 23/2/2023 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain"… | |
| Modificada | Media (6.5) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is… | |
| Modificada | Crítica (9.1) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL.… | |
| Modificada | Media (6.5) | 1.8% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+4 | 5/12/2022 | 17/6/2026 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or… | |
| Modificada | Crítica (9.8) | 4.4% | — | Haxx CurlNetapp Clustered Data OntapNetapp H300s FirmwareNetapp H500s Firmware+5 | 5/12/2022 | 17/6/2026 | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and… | |
| Modificada | Alta (7.8) | 5.8% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. | |
| Modificada | Alta (7.5) | 41% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. | |
| Modificada | Alta (7.5) | 91% | — | OpensslFedoraproject FedoraNetapp Clustered Data OntapNodejs Node.js | 1/11/2022 | 17/6/2026 | A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite… |