Vulnerabilities

Summary — last 7 days

New vulnerabilities3,335▲ 417 vs. last week
Critical / high1,494▲ 172 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)579▲ 105 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.4)18%—OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+293/25/20216/17/2026
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict…
ModifiedMedium (5.9)64%—OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+1023/25/20216/17/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModifiedMedium (4.9)0.67%—Sonicwall Sma100 Firmware3/13/20216/17/2026
A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
ModifiedHigh (8.8)1.8%—Sonicwall Sma100 Firmware3/13/20216/17/2026
A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
ModifiedMedium (5.3)0.98%—Sonicwall Sma100 FirmwareSonicwall Sonicos9/30/20206/17/2026
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names…