Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

714 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.54%—Broadcom Fabric Operating System26/6/202417/6/2026
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the…
ModificadaMedia (5.5)0.11%—Broadcom Fabric Operating System26/6/202417/6/2026
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is…
AnalizadaMedia (4.3)0.30%—Broadcom Fabric Operating System26/6/202417/6/2026
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
AplazadaMedia (5.3)0.30%—Saleswonder 5 Stars Rating FunnelAI9/6/202417/6/2026
Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.
ModificadaAlta (7.8)0.26%—A10networks Advanced Core Operating System6/6/202417/6/2026
A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of A10 Thunder ADC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
ModificadaAlta (8.8)3.0%—A10networks Advanced Core Operating System6/6/202417/6/2026
A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the CsrRequestView class.…
AnalizadaCrítica (9.8)0.44%—Lesterchan Wp-postratings4/6/202417/6/2026
Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
AplazadaMedia (6.4)0.38%—Reviews AND Rating Google ReviewsAI25/5/202417/6/2026
The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…
AnalizadaAlta (8.8)2.1%—A10networks Advanced Core Operating System3/5/202417/6/2026
A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaMedia (6.5)2.5%—A10networks Advanced Core Operating System3/5/202417/6/2026
A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
AplazadaMedia (5.3)0.42%—Danielpowney Multi RatingAI24/4/202417/6/2026
Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi Rating: from n/a through 5.0.6.
AplazadaMedia (5.3)0.43%—Shoaib Saleem WP Post RatingAI24/4/202417/6/2026
Missing Authorization vulnerability in Shoaib Saleem WP Post Rating allows Functionality Misuse.This issue affects WP Post Rating: from n/a through 2.5.
AplazadaAlta (7.5)0.58%—Saleswonder 5 Stars Rating FunnelAI10/4/202417/6/2026
Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.
AnalizadaMedia (6.1)0.43%—Lesterchan Wp-postratings8/4/202416/6/2026
A vulnerability was found in GamerZ WP-PostRatings up to 1.64. It has been classified as problematic. This affects an unknown part of the file wp-postratings.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.65 is able to address this issue. The…
ModificadaMedia (4.3)0.18%—Broadcom Fabric Operating System5/4/202417/6/2026
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
AnalizadaMedia (6.3)2.9%—Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.
ModificadaAlta (7.3)3.9%💥 PoCApache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
ModificadaCrítica (9.8)1.2%—Broadcom Fabric Operating System4/4/202417/6/2026
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.
AplazadaMedia (5.9)0.32%—Wouter Dijkstra DD RatingAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wouter Dijkstra DD Rating allows Stored XSS.This issue affects DD Rating: from n/a through 1.7.1.
AplazadaMedia (5.3)0.43%—Quicoto Thumbs RatingAI31/3/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.0.
AnalizadaAlta (8.6)36%—Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+1027/3/202417/6/2026
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.…
AnalizadaMedia (6.1)0.65%—Remyandrade Product Review/rating System17/3/202417/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Product Review Rating System 1.0. Affected is an unknown function of the component Rate Product Handler. The manipulation of the argument Your Name/Comment leads to cross site scripting. It is possible to launch the attack remotely. The…
ModificadaMedia (6.1)0.40%—Dev4press GD Rating System29/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating System: from n/a through 3.5.
AnalizadaMedia (6.6)0.32%—Cisco Firepower Extensible Operating SystemCisco Nx-osCisco Unified Computing System29/2/202417/6/2026
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame.…
AnalizadaAlta (8.1)0.58%—Opennav Nav2Openrobotics Robot Operating System20/2/202417/6/2026
Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.
Orbitaley — Vulnerabilidades