Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.42%—Envasadora H2O Eireli Soda CristalAI8/9/202517/6/2026
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via a crafted HTTP request.
AplazadaAlta (7.1)0.15%—Olar Marius Vasaio Vasaio QR CodeAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Olar Marius Vasaio QR Code vasaio-qr-code allows Stored XSS.This issue affects Vasaio QR Code: from n/a through <= 1.2.5.
ModificadaMedia (5.7)0.23%—Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance13/2/202317/6/2026
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
ModificadaAlta (8.8)1.4%—Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance11/2/202317/6/2026
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system.
ModificadaMedia (6.5)0.74%—Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell EMC Vasa Provider Virtual Appliance+418/1/202317/6/2026
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.
ModificadaAlta (8)0.33%—Dell Evasa Provider Virtual ApplianceDell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360+431/8/202217/6/2026
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.
ModificadaAlta (7.8)0.24%—Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+321/1/202217/6/2026
The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.
ModificadaAlta (8)0.36%—Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+321/1/202217/6/2026
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
ModificadaAlta (7.5)54%—Eclipse JettyOracle Autovue FOR Agile Product Lifecycle ManagementOracle Communications Cloud Native Core PolicyOracle Communications Element Manager+171/4/202117/6/2026
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
ModificadaMedia (5.3)82%—Eclipse JettyNetapp Cloud ManagerNetapp E-series Performance AnalyzerNetapp E-series Santricity OS Controller+131/4/202117/6/2026
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive…
ModificadaBaja (2.7)4.2%—Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+191/4/202117/6/2026
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
ModificadaMedia (6.1)41%—Apache CXFNetapp Snap Creator FrameworkNetapp Vasa Provider FOR Clustered Data OntapOracle Business Intelligence+212/11/202017/6/2026
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all…
ModificadaAlta (7)4.4%—Eclipse JettyNetapp Snap Creator FrameworkNetapp SnapcenterNetapp Vasa Provider+1423/10/202017/6/2026
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared…
ModificadaAlta (7.5)2.1%—NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+1317/4/202017/6/2026
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
ModificadaAlta (8.1)4.5%—Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+108/5/201917/6/2026
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
ModificadaAlta (8.1)5.1%—Linux KernelCanonical Ubuntu LinuxDebian LinuxF5 Traffix Signaling Delivery Controller+97/5/201917/6/2026
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
ModificadaAlta (7.7)4.3%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+1025/4/201917/6/2026
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net…
ModificadaMedia (5.5)0.54%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+924/4/201917/6/2026
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial…
ModificadaAlta (7)0.37%—Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ+623/4/201917/6/2026
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.
ModificadaMedia (5.3)5.9%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+2222/4/201917/6/2026
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.…
ModificadaMedia (5.3)4.1%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+2122/4/201917/6/2026
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in…
ModificadaMedia (4.7)0.34%—Linux KernelDebian LinuxNetapp Active IQ Unified Manager FOR Vmware VsphereNetapp HCI Management Node+622/4/201917/6/2026
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before…
ModificadaMedia (5.5)1.8%—GNU BinutilsNetapp Vasa ProviderF5 Traffix Signaling Delivery Controller10/12/201817/6/2026
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.
ModificadaMedia (5.5)2.0%—GNU BinutilsNetapp Vasa Provider7/12/201817/6/2026
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.
ModificadaAlta (7.8)1.6%—GNU BinutilsNetapp Vasa ProviderCanonical Ubuntu Linux7/12/201817/6/2026
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.