Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Netapp Hyper Converged Infrastructure Compute NodeNetapp Element Plug-in FOR Vcenter Server29/4/201917/6/2026
Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaAlta (7.5)3.6%—Net-snmpNetapp Cloud BackupNetapp Hyper Converged InfrastructureNetapp Storagegrid Webscale+38/10/201817/6/2026
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (6.5)18%—Net-snmpDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+68/10/201817/6/2026
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaAlta (7.5)3.9%—Palletsprojects FlaskNetapp Active IQNetapp Hyper Converged InfrastructureNetapp Ontap Select Deploy Utility20/8/201817/6/2026
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability…
ModificadaAlta (8.8)2.7%—Eclipse JettyNetapp E-series Santricity Management Plug-insNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB Services Proxy+822/6/201817/6/2026
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the…