Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.73% | — | Dell Smartfabric Os10 | 28/9/2022 | 17/6/2026 | Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause a system crash by running particular security scans. | |
| Modificada | Baja (3.7) | 0.43% | — | Dell Smartfabric Os10 | 28/9/2022 | 17/6/2026 | Dell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to limited switch configuration data. The vulnerability could be leveraged by attackers to conduct… | |
| Modificada | Media (4.9) | 0.59% | — | Dell Smartfabric Os10 | 28/9/2022 | 17/6/2026 | Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and access the REST API with admin… | |
| Modificada | Alta (7.5) | 1.0% | — | Mcwebserver Minecraft MOD FOR Fabric AND Quilt Project Mcwebserver Minecraft MOD FOR Fabric AND QuiltMcwebserver Minecraft MOD FOR Forge Project Mcwebserver Minecraft MOD FOR Forge | 21/9/2022 | 17/6/2026 | McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone… | |
| Modificada | Crítica (9.8) | 2.7% | — | Sourcefabric Rpi-jukebox-rfid | 30/8/2022 | 17/6/2026 | RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file. | |
| Modificada | Crítica (9.8) | 0.97% | — | Dell Smartfabric Storage Software | 30/8/2022 | 17/6/2026 | SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access and perform actions on the affected system. | |
| Modificada | Media (6.7) | 0.33% | 💥 PoC | Redhat Fabric8-kubernetesRedhat A-mq StreamsRedhat Build OF QuarkusRedhat Descision Manager+5 | 24/8/2022 | 17/6/2026 | A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML. | |
| Modificada | Media (5.3) | 1.1% | — | Hyperledger Fabric | 18/8/2022 | 17/6/2026 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the… | |
| Modificada | Media (5.5) | 0.23% | — | Broadcom Fabric Operating System | 5/8/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published… | |
| Modificada | Media (4.8) | 0.43% | — | HPE Flexnetwork 5130 EI FirmwareHPE Flexfabric 5945 Firmware | 8/7/2022 | 17/6/2026 | A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE… | |
| Modificada | Alta (7.5) | 2.1% | — | Hyperledger Fabric | 7/7/2022 | 17/6/2026 | Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to an orderer it may crash the orderer node. A fix has been added in commit 0f1835949 which checks for missing consensus messages and returns an error to the consensus… | |
| Modificada | Media (6.7) | 1.1% | — | Microsoft Service Fabric | 15/6/2022 | 17/6/2026 | Executive Summary An Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers. Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container. All Service Fabric and Docker versions are impacted. | |
| Modificada | Media (6.5) | 3.8% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp HCI Bootstrap OS+9 | 2/6/2022 | 17/6/2026 | A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. | |
| Modificada | Alta (7.5) | 3.2% | — | Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+8 | 2/6/2022 | 17/6/2026 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. | |
| Modificada | Media (5.7) | 1.8% | — | Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+8 | 2/6/2022 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers. | |
| Modificada | Alta (8.1) | 2.2% | — | Haxx CurlDebian LinuxNetapp Clustered Data OntapNetapp Solidfire & HCI Management Node+8 | 26/5/2022 | 17/6/2026 | An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S),… | |
| Modificada | Media (5.4) | 0.52% | — | Tibco BPM EnterpriseTibco BPM Enterprise Distribution FOR Silver Fabric | 17/5/2022 | 17/6/2026 | The Workspace client component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow low privileged attackers with network access to execute scripts targeting the affected… | |
| Modificada | Alta (7.5) | 2.5% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without… | |
| Modificada | Media (5.9) | 1.1% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the… | |
| Modificada | Media (5.3) | 1.2% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that… | |
| Modificada | Alta (7.3) | 83% | 💥 PoC | Siemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+31 | 3/5/2022 | 17/6/2026 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the… | |
| Modificada | Alta (7.8) | 0.54% | — | Linux KernelOracle Communications Cloud Native Core Binding Support FunctionDebian LinuxBroadcom Brocade Fabric Operating System Firmware+5 | 23/3/2022 | 17/6/2026 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control… | |
| Modificada | Media (6.5) | 0.82% | — | Broadcom Fabric Operating System | 18/3/2022 | 17/6/2026 | The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An attacker who has compromised the FOS system may utilize this weakness to capture sensitive information, such as user… | |
| Modificada | Media (6.5) | 0.70% | — | Broadcom Fabric Operating System | 18/3/2022 | 17/6/2026 | A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files. | |
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Fabric Operating System | 21/2/2022 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system. |