Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
–

106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.6%—Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+47/7/202217/6/2026
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good…
ModificadaBaja (2.7)1.3%—Eclipse JettyDebian LinuxNetapp Element Plug-in FOR Vcenter ServerManagement Services FOR Element Software AND Netapp HCI+37/7/202217/6/2026
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.
ModificadaAlta (7.5)2.7%—Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+82/6/202217/6/2026
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
ModificadaMedia (5.3)2.7%—Haxx CurlNetapp HCI Bootstrap OSNetapp Clustered Data OntapNetapp Solidfire, Enterprise SDS & HCI Storage Node+72/6/202217/6/2026
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided, a more…
ModificadaAlta (8.1)3.8%—Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Oncommand Insight+102/6/202217/6/2026
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
ModificadaAlta (7.8)0.80%—Linux KernelDebian LinuxNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+912/5/202217/6/2026
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
ModificadaAlta (7.5)77%—Oracle GraalvmOracle JDKDebian LinuxNetapp 7-mode Transition Tool+1219/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with…
ModificadaMedia (5.3)2.5%—Oracle GraalvmOracle JDKOracle JREDebian Linux+1319/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows…
ModificadaMedia (5.3)3.2%—Oracle GraalvmOracle JDKOracle JREDebian Linux+1319/4/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows…
ModificadaAlta (7.8)0.41%—Linux KernelNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management NodeNetapp HCI Compute Node Firmware+911/4/202217/6/2026
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
ModificadaAlta (7)0.33%—Linux KernelRedhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+118/4/202217/6/2026
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
ModificadaAlta (7.5)52%—NokogiriPythonZlibDebian Linux+2325/3/202214/7/2026
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
ModificadaMedia (6.5)4.7%—PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+1610/3/202217/6/2026
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to…
ModificadaMedia (6.5)1.2%—Linux KernelRedhat Enterprise LinuxDebian LinuxOracle Communications Cloud Native Core Binding Support Function+142/3/202217/6/2026
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
AnalizadaAlta (7.4)6.9%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+1718/2/202230/7/2026
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this…
ModificadaAlta (7.5)8.3%—PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+69/2/202217/6/2026
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a…
ModificadaMedia (6.6)0.32%—Intel C620a Series FirmwareIntel C620 Series FirmwareIntel C240 Series FirmwareIntel Atom P5000 Series Firmware+129/2/202217/6/2026
Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0,…
AnalizadaAlta (7.5)3.6%—Linux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+2225/12/20215/8/2026
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
ModificadaAlta (8.1)60%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+2211/6/202117/6/2026
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at…
ModificadaMedia (5.3)3.0%—Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+1811/6/202117/6/2026
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if…
ModificadaMedia (6.7)0.30%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+49/6/202117/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.4)0.27%—Intel BiosSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e Firmware+149/6/202117/6/2026
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaBaja (3.3)0.38%—Intel MicrocodeDebian LinuxNetapp Fas/aff BiosNetapp HCI Compute Node Bios+19/6/202117/6/2026
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)0.40%—Intel MicrocodeDebian LinuxNetapp Fas/aff BiosNetapp HCI Compute Node Bios+19/6/202117/6/2026
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.30%—Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+59/6/202117/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.