Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2573▼ 368 respecto a la semana anterior
Críticas / altas1324▲ 44 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.36% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H410c Firmware+5 | 26/5/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.5) | 2.9% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorNetapp E-series Santricity OS Controller+13 | 25/5/2022 | 17/6/2026 | An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. | |
| Analizada | Alta (7) | 0.53% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+6 | 18/5/2022 | 26/8/2026 | A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. | |
| Modificada | Alta (7.8) | 0.93% | — | Linux KernelDebian LinuxCanonical Ubuntu LinuxNetapp H300s Firmware+7 | 17/5/2022 | 17/6/2026 | Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions. | |
| Modificada | Alta (7.8) | 0.81% | — | Linux KernelDebian LinuxNetapp H410c FirmwareNetapp H300s Firmware+6 | 16/5/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.5) | 2.5% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without… | |
| Modificada | Media (5.9) | 1.1% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the… | |
| Modificada | Media (5.3) | 1.2% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that… | |
| Modificada | Alta (7.3) | 83% | — | Siemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+31 | 3/5/2022 | 17/6/2026 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the… | |
| Modificada | Alta (7.1) | 0.40% | — | Linux KernelDebian LinuxRedhat Enterprise LinuxNetapp H300s Firmware+7 | 29/4/2022 | 5/8/2026 | A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information. | |
| Modificada | Alta (7) | 0.24% | — | Linux KernelRedhat Enterprise LinuxDebian LinuxNetapp H300s Firmware+7 | 29/4/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Alta (7.8) | 0.38% | — | Linux KernelNetapp H300e FirmwareNetapp H300s FirmwareNetapp H410c Firmware+5 | 13/4/2022 | 17/6/2026 | drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release. | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management NodeNetapp HCI Compute Node Firmware+9 | 11/4/2022 | 17/6/2026 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | |
| Modificada | Alta (7) | 0.33% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+11 | 8/4/2022 | 17/6/2026 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. | |
| Modificada | Media (5.5) | 0.32% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp H300s Firmware+7 | 3/4/2022 | 17/6/2026 | mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. | |
| Modificada | Media (5.5) | 0.40% | — | Linux KernelDebian LinuxFedoraproject FedoraNetapp H300s Firmware+7 | 3/4/2022 | 17/6/2026 | usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. | |
| Modificada | Alta (7.8) | 0.37% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+5 | 30/3/2022 | 17/6/2026 | An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Analizada | Alta (8.6) | 0.50% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraCanonical Ubuntu Linux+8 | 29/3/2022 | 13/8/2026 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 | |
| Analizada | Alta (7.8) | 8.8% | ⚠ Explotación activa | Linux KernelFedoraproject FedoraNetapp H300e FirmwareNetapp H300s Firmware+9 | 25/3/2022 | 27/8/2026 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system. | |
| Modificada | Alta (7.8) | 0.36% | — | Linux KernelFedoraproject FedoraNetapp H300e FirmwareNetapp H300s Firmware+6 | 25/3/2022 | 17/6/2026 | A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system. | |
| Modificada | Alta (8.8) | 68% | — | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+26 | 25/3/2022 | 17/6/2026 | A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access… | |
| Analizada | Alta (7.8) | 0.38% | — | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+34 | 25/3/2022 | 5/8/2026 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system. | |
| Modificada | Alta (8) | 1.6% | — | Linux KernelFedoraproject FedoraNetapp H300e FirmwareNetapp H300s Firmware+6 | 25/3/2022 | 17/6/2026 | An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system. | |
| Modificada | Media (6.8) | 3.4% | — | ISC BindFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+8 | 23/3/2022 | 17/6/2026 | BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The… | |
| Modificada | Alta (7.5) | 1.3% | — | ISC BindNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+5 | 23/3/2022 | 17/6/2026 | Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check. |