Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.3)83%—Siemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+313/5/202217/6/2026
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the…
ModificadaCrítica (9.1)42%—Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+414/3/202217/6/2026
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
ModificadaCrítica (9.8)28%—Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+414/3/202217/6/2026
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
ModificadaMedia (5.9)3.8%—OpensslDebian LinuxOracle Health Sciences Inform PublisherOracle JD Edwards Enterpriseone Tools+428/1/202217/6/2026
There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks…
ModificadaMedia (5.9)100%—Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
AnalizadaCrítica (9)100%⚠ Explotación activaResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaAlta (7.5)3.3%—Python Urllib3Fedoraproject FedoraOracle Enterprise Manager OPS CenterOracle Instantis Enterprisetrack+129/6/202117/6/2026
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
ModificadaAlta (7.5)51%—Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+215/6/202117/6/2026
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was…
ModificadaMedia (5.3)53%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+210/6/202117/6/2026
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
ModificadaCrítica (9.8)68%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+410/6/202117/6/2026
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
ModificadaAlta (7.5)65%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+210/6/202117/6/2026
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
ModificadaAlta (7.3)55%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+210/6/202117/6/2026
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with…
ModificadaAlta (7.5)49%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center+210/6/202117/6/2026
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service
ModificadaMedia (5.3)60%—Apache Http ServerFedoraproject FedoraOracle Enterprise Manager OPS CenterOracle Instantis Enterprisetrack+110/6/202117/6/2026
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization…
ModificadaAlta (7.5)1.9%—WiresharkOracle Enterprise Manager OPS CenterOracle Instantis EnterprisetrackOracle ZFS Storage Appliance KIT+17/6/202117/6/2026
Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
ModificadaAlta (8.8)77%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1328/5/202117/6/2026
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's…
ModificadaAlta (8.8)22%—Xmlsoft Libxml2Debian LinuxRedhat Jboss Core ServicesRedhat Enterprise Linux+1418/5/202117/6/2026
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
ModificadaMedia (5.9)3.5%—Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxDebian Linux+1514/5/202117/6/2026
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this…
ModificadaMedia (5.9)7.4%—OpensslDebian LinuxTenable Nessus Network MonitorTenable.sc+1916/2/202117/6/2026
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is…
ModificadaAlta (7.5)51%—OpensslDebian LinuxTenable LOG Correlation EngineTenable Nessus Network Monitor+1716/2/202117/6/2026
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output…
ModificadaBaja (3.7)3.0%—OpensslOracle Business IntelligenceOracle Enterprise Manager FOR Storage ManagementOracle Enterprise Manager OPS Center+416/2/202117/6/2026
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed…
ModificadaMedia (5.9)41%—PythonFedoraproject FedoraDebian LinuxNetapp Cloud Backup+815/2/202117/6/2026
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query…
ModificadaAlta (8.2)1.2%—Oracle Data IntegratorOracle Enterprise Manager OPS CenterOracle Workflow20/1/202117/6/2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks require human…
ModificadaMedia (5)0.32%—Oracle Enterprise Manager OPS CenterOracle Hyperion Infrastructure TechnologyOracle ZFS Storage Appliance20/1/202117/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: RAS subsystems). The supported version that is affected is 8.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise…