Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
2520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.3) | 0.25% | — | Netapp StoragegridAI | 28/8/2026 | 1/9/2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service. | |
| Analizada | Alta (8.7) | 0.53% | — | Netapp Ontap | 22/7/2026 | 20/8/2026 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. | |
| Analizada | Media (5.3) | 0.24% | — | Netapp Active IQ Onecollect | 3/6/2026 | 22/7/2026 | Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | |
| Analizada | Media (5.3) | 0.24% | — | Netapp Active IQ Config Advisor | 3/6/2026 | 22/7/2026 | Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | |
| Analizada | Baja (2.3) | 0.18% | — | Netapp Storagegrid | 20/4/2026 | 8/7/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to. | |
| Analizada | Media (5.3) | 0.20% | — | Netapp Ontap | 5/3/2026 | 17/6/2026 | ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission. | |
| Aplazada | Alta (7.1) | 0.28% | — | Netapp StoragegridAI | 18/2/2026 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with… | |
| Analizada | Media (6.9) | 0.22% | — | Netapp Ontap | 12/1/2026 | 17/6/2026 | ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none. | |
| Analizada | Media (5.4) | 0.19% | — | Netapp Storagegrid | 19/9/2025 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege escalation vulnerability. Successful exploit could allow an unauthorized authenticated attacker to discover Grid node names and IP addresses or modify Storage Grades. | |
| Analizada | Media (5.3) | 0.39% | — | Netapp Storagegrid | 19/9/2025 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of Service on the Admin node. | |
| Analizada | Alta (7.5) | 0.34% | — | Netapp Storagegrid | 19/9/2025 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to change the password of any Grid Manager or Tenant Manager… | |
| Analizada | Media (6.4) | 0.24% | — | Netapp Storagegrid | 19/9/2025 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific… | |
| Analizada | Alta (7.8) | 0.12% | — | Netapp SAN Host Utilities | 7/8/2025 | 17/6/2026 | The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges. | |
| Analizada | Alta (7.5) | 0.95% | — | Apache HttpclientNetapp Ontap Tools | 24/4/2025 | 17/6/2026 | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release | |
| Modificada | Media (6.8) | 0.50% | — | Oracle Mysql ClusterOracle Mysql ClientNetapp Active IQ Unified ManagerNetapp Snapcenter | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client.… | |
| Modificada | Media (4.8) | 0.58% | — | Oracle Graalvm FOR JDKOracle JDKOracle JRENetapp Bootstrap OS | 15/4/2025 | 17/6/2026 | Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful… | |
| Analizada | Media (4.9) | 0.84% | — | Oracle Mysql ServerNetapp Snapcenter | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability… | |
| Analizada | Media (5.3) | 1.3% | — | Apache POINetapp Active IQ Unified Manager | 9/4/2025 | 17/6/2026 | Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading… | |
| Modificada | Media (6.3) | 0.84% | — | PHPNetapp Ontap | 30/3/2025 | 17/6/2026 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is… | |
| Modificada | Media (6.3) | 0.54% | — | PHPNetapp Ontap | 30/3/2025 | 17/6/2026 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted. | |
| Modificada | Media (6.3) | 0.49% | — | PHPNetapp Ontap | 30/3/2025 | 17/6/2026 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers. | |
| Analizada | Crítica (9.9) | 0.65% | — | Netapp Snapcenter | 24/3/2025 | 17/6/2026 | SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed. | |
| Analizada | Media (4.4) | 0.39% | — | VIMNetapp Bootstrap OS | 13/3/2025 | 17/6/2026 | Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been fixed as of Vim patch v9.1.1198. | |
| Modificada | Crítica (9.3) | 65% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document… | |
| Modificada | Crítica (9.3) | 21% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document… |