Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
484 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.27% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, “root” account access is disabled. | |
| Modificada | Media (5.5) | 1.3% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 30/3/2023 | 17/6/2026 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the… | |
| Modificada | Media (5.9) | 1.9% | — | Haxx LibcurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapBroadcom Brocade Fabric Operating System Firmware+5 | 30/3/2023 | 17/6/2026 | A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads… | |
| Modificada | Alta (8.8) | 2.2% | — | Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerBroadcom Brocade Fabric Operating System Firmware+5 | 30/3/2023 | 17/6/2026 | A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw… | |
| Modificada | Crítica (9.8) | 2.3% | — | Openbsd OpensshNetapp Brocade Fabric Operating SystemNetapp HCI Bootstrap OSNetapp Solidfire Element OS | 17/3/2023 | 14/7/2026 | ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | |
| Modificada | Media (6.7) | 0.22% | — | Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+8 | 23/2/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands… | |
| Analizada | Alta (7.5) | 83% | ⚠ Explotación activa💥 Exploit | Terra-master Terramaster Operating System | 7/2/2023 | 17/6/2026 | TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response. | |
| Modificada | Crítica (9.8) | 14% | — | Gullseye Terminal Operating System | 10/1/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13. | |
| Modificada | Crítica (9.8) | 1.6% | — | Broadcom Fabric Operating SystemBrocade Fabric Operating System | 8/12/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address. | |
| Modificada | Media (6.7) | 0.29% | — | Cisco Secure Firewall Threat DefenseCisco Firepower Extensible Operating System | 15/11/2022 | 11/8/2026 | A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could… | |
| Modificada | Alta (7.8) | 0.34% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows, allowing arbitrary code execution as the root user account. | |
| Modificada | Alta (7.8) | 0.35% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in fab_seg.c.h libraries of all Brocade Fabric OS versions before Brocade Fabric OS v9.1.1, v9.0.1e, v8.2.3c, v8.2.0_cbn5, 7.4.2j could allow local authenticated attackers to exploit stack-based buffer overflows and execute arbitrary code as the root user account. | |
| Modificada | Alta (8.8) | 1.6% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands. | |
| Modificada | Alta (7.8) | 0.20% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload, license, and “fosexec”. | |
| Modificada | Media (5.5) | 0.22% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands “configshow” and “supportlink”. | |
| Modificada | Media (5.5) | 0.22% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”. | |
| Modificada | Alta (8.8) | 0.19% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges. | |
| Modificada | Alta (7.2) | 1.4% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitrary code on the Brocade switch. | |
| Modificada | Media (6.5) | 0.21% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file. | |
| Modificada | Alta (8.8) | 0.77% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin… | |
| Modificada | Alta (7.8) | 0.98% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.88% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.83% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.83% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.93% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Information Disclosure Vulnerability |