Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.18% | — | Oracle Solaris | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this… | |
| Modificada | Baja (3.1) | 0.34% | — | Oracle Solaris | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via rquota to compromise Oracle Solaris. Successful attacks require human interaction from a… | |
| Modificada | Alta (7.5) | 0.67% | — | Arista EOS | 29/8/2023 | 17/6/2026 | On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload. | |
| Modificada | Media (6.5) | 0.48% | — | Arista EOS | 29/8/2023 | 17/6/2026 | On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place. | |
| Modificada | Alta (7.8) | 0.19% | — | Oracle Solaris | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful… | |
| Modificada | Media (6.9) | 0.29% | — | BD Alaris Systems Manager | 13/7/2023 | 17/6/2026 | Alaris Systems Manager does not perform input validation during the Device Import Function. | |
| Modificada | Alta (8.2) | 0.44% | — | BD Alaris Systems Manager | 13/7/2023 | 17/6/2026 | A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. | |
| Modificada | Media (6.7) | 0.18% | — | BD Alaris Guardrails Editor | 13/7/2023 | 17/6/2026 | A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs. | |
| Modificada | Media (6.1) | 0.19% | — | BD Alaris 8015 PCU Firmware | 13/7/2023 | 17/6/2026 | The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running. | |
| Modificada | Media (6.8) | 0.30% | — | BD Alaris 8015 PCU Firmware | 13/7/2023 | 17/6/2026 | The configuration from the PCU can be modified without authentication using physical connection to the PCU. | |
| Modificada | Media (5.7) | 0.18% | — | BD Alaris 8015 PCU Firmware | 13/7/2023 | 17/6/2026 | The firmware update package for the wireless card is not properly signed and can be modified. | |
| Modificada | Alta (8.1) | 0.47% | — | Arista Cloudvision Portal | 13/6/2023 | 17/6/2026 | On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision… | |
| Modificada | Alta (7.3) | 0.16% | — | BD Alaris Infusion Central | 13/6/2023 | 17/6/2026 | The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data. | |
| Modificada | Alta (7.5) | 0.62% | — | Arista EOS | 5/6/2023 | 17/6/2026 | On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart. | |
| Modificada | Media (4.8) | 0.58% | — | Simple Mobile Comparison Website Project Simple Mobile Comparison Website | 28/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_field. The manipulation of the argument Field Name leads to cross site scripting. The attack may be initiated… | |
| Modificada | Media (6.5) | 0.60% | — | Arista EOSArista Ceos-labArista CloudeosArista Veos-lab | 25/4/2023 | 17/6/2026 | On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access… | |
| Modificada | Baja (3.3) | 0.22% | — | Oracle Solaris | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks… | |
| Modificada | Alta (7.7) | 0.23% | — | Oracle Solaris | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks… | |
| Modificada | Media (6.5) | 0.66% | — | Oracle Solaris | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Libraries). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in… | |
| Modificada | Alta (7.8) | 0.23% | — | Oracle Solaris | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Core). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this… | |
| Modificada | Baja (1.8) | 0.19% | — | Oracle Solaris | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: IPS repository daemon). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful… | |
| Modificada | Alta (7) | 0.17% | — | Oracle Solaris | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of… | |
| Modificada | Alta (7.8) | 0.24% | — | Arista EOS | 13/4/2023 | 17/6/2026 | On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in… | |
| Modificada | Alta (7.5) | 0.78% | — | Arista Cloudeos | 12/4/2023 | 17/6/2026 | On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding… | |
| Modificada | Alta (7.5) | 0.84% | — | Arista EOS | 12/4/2023 | 17/6/2026 | On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other… |