Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.7)2.3%—Oracle OpenjdkOracle JDKOracle JREDebian Linux+1221/10/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaCrítica (9.8)1.9%—Intel Standard ManageabilityIntel Active Management Technology FirmwareNetapp Steelstore Cloud Integrated Storage10/9/202017/6/2026
Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via network access. On un-provisioned systems, an authenticated user may…
ModificadaMedia (4.3)3.7%—ISC BindNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu LinuxDebian Linux+221/8/202017/6/2026
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these…
ModificadaAlta (7.5)6.4%—ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+321/8/202017/6/2026
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with…
ModificadaMedia (6.5)5.6%—ISC BindFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+421/8/202017/6/2026
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an…
ModificadaAlta (7.5)3.0%—ISC BindOpensuse LeapCanonical Ubuntu LinuxSynology DNS Server+121/8/202017/6/2026
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
ModificadaAlta (7.5)3.7%—ISC BindOpensuse LeapNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu Linux21/8/202017/6/2026
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
ModificadaBaja (3.7)5.3%—Linux KernelOpensuse LeapFedoraproject FedoraDebian Linux+1130/7/202017/6/2026
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
AnalizadaAlta (7.4)13%—Openbsd OpensshNetapp A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+524/7/202017/6/2026
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking…
ModificadaAlta (7.8)0.34%—Linux KernelXENNetapp Cloud BackupNetapp Steelstore Cloud Integrated Storage+120/7/202017/6/2026
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka…
ModificadaAlta (8.3)4.2%—Oracle JDKOracle JRENetapp 7-mode Transition ToolNetapp Active IQ Unified Manager+1115/7/202017/6/2026
Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a…
AnalizadaMedia (5.3)4.3%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1915/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaAlta (7.4)3.8%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1615/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise…
AnalizadaAlta (8.3)3.9%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1615/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
AnalizadaBaja (3.7)3.3%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1715/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
AnalizadaBaja (3.7)4.3%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1715/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
AnalizadaBaja (3.7)4.3%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1715/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
AnalizadaBaja (3.7)3.4%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1615/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE,…
AnalizadaMedia (4.8)3.0%—Oracle OpenjdkOracle JDKOracle JREFedoraproject Fedora+1615/7/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaMedia (5.9)2.1%—Openbsd OpensshNetapp AFF A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+529/6/202017/6/2026
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6…
ModificadaMedia (4.9)3.4%—NTPOpensuse LeapNetapp Cloud BackupNetapp Steelstore Cloud Integrated Storage+1224/6/202017/6/2026
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
ModificadaMedia (4.9)2.1%—ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+217/6/20201/9/2026
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*")…
ModificadaMedia (4.9)1.8%—ISC BindOpensuse LeapNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu Linux17/6/202017/6/2026
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
ModificadaAlta (8.1)4.5%—Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Steelstore Cloud Integrated StorageDebian Linux+1016/6/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
ModificadaMedia (5.3)4.2%—PcreApple MacosGitlabOracle Communications Cloud Native Core Policy+1115/6/202017/6/2026
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.