Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
714 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.54% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the… | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is… | |
| Analizada | Media (4.3) | 0.30% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords. | |
| Aplazada | Media (5.3) | 0.30% | — | Saleswonder 5 Stars Rating FunnelAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67. | |
| Modificada | Alta (7.8) | 0.26% | — | A10networks Advanced Core Operating System | 6/6/2024 | 17/6/2026 | A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of A10 Thunder ADC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (8.8) | 3.0% | — | A10networks Advanced Core Operating System | 6/6/2024 | 17/6/2026 | A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the CsrRequestView class.… | |
| Analizada | Crítica (9.8) | 0.44% | — | Lesterchan Wp-postratings | 4/6/2024 | 17/6/2026 | Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91. | |
| Aplazada | Media (6.4) | 0.38% | — | Reviews AND Rating Google ReviewsAI | 25/5/2024 | 17/6/2026 | The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Analizada | Alta (8.8) | 2.1% | — | A10networks Advanced Core Operating System | 3/5/2024 | 17/6/2026 | A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.5) | 2.5% | — | A10networks Advanced Core Operating System | 3/5/2024 | 17/6/2026 | A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Media (5.3) | 0.42% | — | Danielpowney Multi RatingAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi Rating: from n/a through 5.0.6. | |
| Aplazada | Media (5.3) | 0.43% | — | Shoaib Saleem WP Post RatingAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Shoaib Saleem WP Post Rating allows Functionality Misuse.This issue affects WP Post Rating: from n/a through 2.5. | |
| Aplazada | Alta (7.5) | 0.58% | — | Saleswonder 5 Stars Rating FunnelAI | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67. | |
| Analizada | Media (6.1) | 0.43% | — | Lesterchan Wp-postratings | 8/4/2024 | 16/6/2026 | A vulnerability was found in GamerZ WP-PostRatings up to 1.64. It has been classified as problematic. This affects an unknown part of the file wp-postratings.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.65 is able to address this issue. The… | |
| Modificada | Media (4.3) | 0.18% | — | Broadcom Fabric Operating System | 5/4/2024 | 17/6/2026 | Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display. | |
| Analizada | Media (6.3) | 2.9% | — | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. | |
| Modificada | Alta (7.3) | 3.9% | 💥 PoC | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | |
| Modificada | Crítica (9.8) | 1.2% | — | Broadcom Fabric Operating System | 4/4/2024 | 17/6/2026 | Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch. | |
| Aplazada | Media (5.9) | 0.32% | — | Wouter Dijkstra DD RatingAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wouter Dijkstra DD Rating allows Stored XSS.This issue affects DD Rating: from n/a through 1.7.1. | |
| Aplazada | Media (5.3) | 0.43% | — | Quicoto Thumbs RatingAI | 31/3/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.0. | |
| Analizada | Alta (8.6) | 36% | — | Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+10 | 27/3/2024 | 17/6/2026 | When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.… | |
| Analizada | Media (6.1) | 0.65% | — | Remyandrade Product Review/rating System | 17/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Product Review Rating System 1.0. Affected is an unknown function of the component Rate Product Handler. The manipulation of the argument Your Name/Comment leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Media (6.1) | 0.40% | — | Dev4press GD Rating System | 29/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating System: from n/a through 3.5. | |
| Analizada | Media (6.6) | 0.32% | — | Cisco Firepower Extensible Operating SystemCisco Nx-osCisco Unified Computing System | 29/2/2024 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame.… | |
| Analizada | Alta (8.1) | 0.58% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. |