Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.22% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”. | |
| Modificada | Alta (8.8) | 0.19% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges. | |
| Modificada | Alta (7.2) | 1.4% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitrary code on the Brocade switch. | |
| Modificada | Media (6.5) | 0.21% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file. | |
| Modificada | Alta (8.8) | 0.77% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin… | |
| Modificada | Media (4.3) | 0.32% | — | Blazzdev Rate MY Post - WP Rating System | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress. | |
| Modificada | Baja (3.1) | 0.45% | — | Blazzdev Rate MY Post - WP Rating System | 23/9/2022 | 17/6/2026 | Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes. | |
| Modificada | Alta (7.8) | 0.98% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.88% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.83% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.83% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.93% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | |
| Modificada | Media (5.5) | 0.93% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 1.00% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.23% | — | Broadcom Fabric Operating System | 5/8/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published… | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 2.5% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 0.94% | — | 17ido Topidp3000 Topsec Operating System | 14/6/2022 | 17/6/2026 | An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie. | |
| Modificada | Media (6.5) | 3.8% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp HCI Bootstrap OS+9 | 2/6/2022 | 17/6/2026 | A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. | |
| Modificada | Alta (7.5) | 3.2% | — | Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+8 | 2/6/2022 | 17/6/2026 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. | |
| Modificada | Media (5.7) | 1.8% | — | Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+8 | 2/6/2022 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers. | |
| Modificada | Alta (8.1) | 2.2% | — | Haxx CurlDebian LinuxNetapp Clustered Data OntapNetapp Solidfire & HCI Management Node+8 | 26/5/2022 | 17/6/2026 | An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S),… |