Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.3%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+730/3/202317/6/2026
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the…
ModificadaMedia (5.9)1.9%—Haxx LibcurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapBroadcom Brocade Fabric Operating System Firmware+530/3/202317/6/2026
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads…
ModificadaAlta (8.8)2.2%—Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerBroadcom Brocade Fabric Operating System Firmware+530/3/202317/6/2026
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw…
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.
ModificadaAlta (7.5)1.4%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c.
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
ModificadaMedia (5.4)0.56%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
ModificadaAlta (7.8)0.17%—Broadcom Symantec Endpoint Protection20/1/202317/6/2026
Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated
ModificadaAlta (8.8)0.91%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
ModificadaMedia (6.7)0.94%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
ModificadaMedia (5.3)0.71%—Broadcom Symantec Identity Governance AND Administration16/12/202217/6/2026
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
ModificadaMedia (4.9)0.47%—Broadcom Brocade Sannav9/12/202217/6/2026
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.
ModificadaCrítica (9.8)1.6%—Broadcom Fabric Operating SystemBrocade Fabric Operating System8/12/202217/6/2026
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address.
ModificadaAlta (7.5)1.2%💥 PoCBroadcom Symantec Endpoint Protection1/12/202217/6/2026
Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password…
ModificadaCrítica (9.8)0.72%—Broadcom Symantec Endpoint Protection1/12/202217/6/2026
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaAlta (7.8)0.34%—Broadcom Fabric Operating System25/10/202217/6/2026
Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows, allowing arbitrary code execution as the root user account.
ModificadaAlta (7.8)0.35%—Broadcom Fabric Operating System25/10/202217/6/2026
A vulnerability in fab_seg.c.h libraries of all Brocade Fabric OS versions before Brocade Fabric OS v9.1.1, v9.0.1e, v8.2.3c, v8.2.0_cbn5, 7.4.2j could allow local authenticated attackers to exploit stack-based buffer overflows and execute arbitrary code as the root user account.
ModificadaAlta (8.8)1.6%—Broadcom Fabric Operating System25/10/202217/6/2026
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands.
ModificadaAlta (7.8)0.20%—Broadcom Fabric Operating System25/10/202217/6/2026
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload, license, and “fosexec”.
Orbitaley — Vulnerabilidades