Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
931 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Broadcom Symantec Server Management Suite | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. | |
| Modificada | Crítica (9.8) | 1.9% | — | Broadcom Symantec Messaging Gateway | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. | |
| Modificada | Crítica (9.8) | 1.6% | — | Broadcom Symantec Messaging Gateway | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. | |
| Modificada | Crítica (9.8) | 1.8% | — | Broadcom Symantec Deployment Solutions | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. | |
| Modificada | Media (5.5) | 0.33% | — | Broadcom TcpreplayFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 21/12/2023 | 17/6/2026 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service… | |
| Modificada | Alta (8.1) | 0.24% | — | Broadcom Fabric Operating System | 6/12/2023 | 17/6/2026 | Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license… | |
| Modificada | Alta (7.5) | 0.91% | — | Broadcom Reactor Netty | 28/11/2023 | 4/9/2026 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with… | |
| Modificada | Alta (7.5) | 1.1% | — | Broadcom Reactor Netty | 15/11/2023 | 4/9/2026 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static… | |
| Modificada | Media (4.8) | 0.42% | — | Cedcommerce Recently Viewed AND Most Viewed Products | 14/11/2023 | 17/6/2026 | Auth. (Shop Manager+) Stored Cross-Site Scripting (XSS) vulnerability in CedCommerce Recently viewed and most viewed products plugin <= 1.1.1 versions. | |
| Modificada | Media (5.4) | 0.49% | 💥 PoC | Broadcom Clarity | 9/11/2023 | 17/6/2026 | Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function. | |
| Modificada | Alta (7.8) | 0.45% | — | Broadcom LSI Pci-sv92ex Firmware | 10/10/2023 | 17/6/2026 | An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege Escalation to SYSTEM via a Stack Overflow in RTLCopyMemory (IOCTL 0x1b2150). An attacker can exploit this to elevate privileges from a medium-integrity process to SYSTEM. This can… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (4.4) | 0.27% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command. | |
| Analizada | Media (4.4) | 0.17% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg --set -expire -minDiff“. | |
| Modificada | Media (6.5) | 0.24% | — | Broadcom Brocade Sannav | 31/8/2023 | 17/6/2026 | Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be seen in SANnav SupportSave if the capture is performed after an SNMP configuration failure causes an… | |
| Modificada | Crítica (9.8) | 0.90% | — | Broadcom Brocade Sannav | 31/8/2023 | 17/6/2026 | Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization. | |
| Modificada | Media (5.5) | 0.23% | — | Broadcom Brocade Sannav | 31/8/2023 | 17/6/2026 | Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected Brocade SANnav "supportsave" outputs. | |
| Modificada | Alta (7.5) | 0.36% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS. | |
| Modificada | Media (6.1) | 0.42% | — | Bdcom P3310d-2ac Firmware | 29/8/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F Build 69083 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter. | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection | |
| Modificada | Alta (7.5) | 0.57% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file | |
| Modificada | Alta (7.5) | 0.83% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions |