Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.22%—Broadcom Fabric Operating System25/10/202217/6/2026
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”.
ModificadaAlta (8.8)0.19%—Broadcom Fabric Operating System25/10/202217/6/2026
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges.
ModificadaAlta (7.2)1.4%—Broadcom Fabric Operating System25/10/202217/6/2026
A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitrary code on the Brocade switch.
ModificadaMedia (6.5)0.21%—Broadcom Fabric Operating System25/10/202217/6/2026
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.
ModificadaAlta (8.8)0.77%—Broadcom Fabric Operating System25/10/202217/6/2026
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin…
ModificadaMedia (4.3)0.32%—Blazzdev Rate MY Post - WP Rating System23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress.
ModificadaBaja (3.1)0.45%—Blazzdev Rate MY Post - WP Rating System23/9/202217/6/2026
Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes.
ModificadaAlta (7.8)0.98%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.88%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.83%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.83%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.93%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaMedia (5.5)0.93%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaAlta (7.8)1.00%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)1.2%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.23%—Broadcom Fabric Operating System5/8/202217/6/2026
A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published…
ModificadaAlta (7.8)2.2%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaAlta (7.8)2.5%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)2.2%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)2.2%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaCrítica (9.8)0.94%—17ido Topidp3000 Topsec Operating System14/6/202217/6/2026
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.
ModificadaMedia (6.5)3.8%—Haxx CurlFedoraproject FedoraDebian LinuxNetapp HCI Bootstrap OS+92/6/202217/6/2026
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
ModificadaAlta (7.5)3.2%—Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+82/6/202217/6/2026
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
ModificadaMedia (5.7)1.8%—Haxx CurlDebian LinuxNetapp HCI Bootstrap OSNetapp Clustered Data Ontap+82/6/202217/6/2026
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
ModificadaAlta (8.1)2.2%—Haxx CurlDebian LinuxNetapp Clustered Data OntapNetapp Solidfire & HCI Management Node+826/5/202217/6/2026
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S),…
Orbitaley — Vulnerabilidades