Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.23%—Samsung Smart Switch PC9/9/202217/6/2026
DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
ModificadaAlta (7.1)0.16%—Samsung Smart Switch PC9/9/202217/6/2026
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction.
ModificadaMedia (5.8)2.3%—Openvswitch8/9/202217/6/2026
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space…
ModificadaMedia (6.5)0.30%—Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform29/8/202217/6/2026
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts…
ModificadaAlta (7.5)2.0%—OpenvswitchRedhat Enterprise Linux Fast DatapathCanonical Ubuntu LinuxFedoraproject Fedora23/8/202217/6/2026
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
ModificadaCrítica (9.8)76%💥 ExploitMegatech Msnswitch Firmware10/8/202217/6/2026
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
ModificadaMedia (4.3)0.25%—Progress Ipswitch WS FTP Server2/8/202217/6/2026
In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to mitigate the risk of cross-site request forgery (CSRF) attacks.
ModificadaMedia (6.1)0.78%—Progress Ipswitch WS FTP Server2/8/202217/6/2026
In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within…
ModificadaAlta (8.8)0.48%—Hitachienergy Modular Switchgear Monitoring Firmware25/7/202217/6/2026
A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker…
ModificadaAlta (8.8)0.22%—Hitachienergy Modular Switchgear Monitoring Firmware25/7/202217/6/2026
A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CSRF), which if exploited could lead an attacker to gain…
ModificadaMedia (4.3)0.40%—Fortinet FortiproxyFortinet FortivoiceFortinet FortiosFortinet Fortirecorder Firmware+118/7/202217/6/2026
An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; FortiRecorder 6.4.2 and below, 6.0.10 and below; FortiOS 7.0.2 and below, 6.4.8 and below, 6.2.10 and below, 6.0.x; FortiProxy 7.0.0, 2.0.6 and below, 1.2.x, 1.1.x, 1.0.x; FortiVoiceEnterprise 6.4.3…
ModificadaCrítica (9.8)1.3%—Nexans Gigaswitch 641 Desk V5 Sfp-vi FirmwareNexans Gigaswitch 642 Desk V5 Sfp-2vi FirmwareNexans Gigaswitch V5 2tp(pd-f+) Sfp-vi 54vdc FirmwareNexans Gigaswitch V5 2tp(pse+) Sfp-vi 54vdc Firmware+917/7/202217/6/2026
libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
ModificadaMedia (6.8)0.24%—Cisco Catalyst Digital Building Series Switches FirmwareCisco IOS Rommon15/4/202217/6/2026
Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device from booting, resulting in a permanent denial of service (DoS) condition. For more information…
ModificadaAlta (7.8)0.24%—Samsung Smart Switch PC11/4/202217/6/2026
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.
ModificadaMedia (5.3)0.90%—Sangoma Switchvox14/2/202217/6/2026
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction. Users information such as first name, last name, acount id, server uuid, email address, profile image, number, timestamps, etc can be extracted by sending an…
ModificadaAlta (8.8)0.99%—Phoenixcontact FL Switch 2005 FirmwarePhoenixcontact FL Switch 2008 FirmwarePhoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 Firmware+612/2/202217/6/2026
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
ModificadaMedia (6.1)0.88%—Pluginus Woocommerce Currency Switcher10/1/202217/6/2026
The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.7)0.52%—Fortinet FortiadcFortinet FortianalyzerFortinet FortimailFortinet Fortimanager+98/12/202117/6/2026
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
ModificadaMedia (6.5)0.38%—UI Unifi Switch Firmware7/12/202117/6/2026
A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the network to perform a Deny of Service (DoS) attack on the affected switch.This vulnerability is fixed in UniFi Switch firmware 5.76.6 and later.
ModificadaMedia (6.1)0.82%—Woocommerce Currency Switcher6/12/202117/6/2026
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
ModificadaCrítica (9.8)4.6%💥 PoCCisco Catalyst PON Switch Cgp-ont-1p FirmwareCisco Catalyst PON Switch Cgp-ont-4p FirmwareCisco Catalyst PON Switch Cgp-ont-4pvc FirmwareCisco Catalyst PON Switch Cgp-ont-4tvcw Firmware+14/11/202117/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform…
ModificadaAlta (7.5)1.4%—Cisco Catalyst PON Switch Cgp-ont-1p FirmwareCisco Catalyst PON Switch Cgp-ont-4p FirmwareCisco Catalyst PON Switch Cgp-ont-4pvc FirmwareCisco Catalyst PON Switch Cgp-ont-4tvcw Firmware+14/11/202117/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform…
ModificadaCrítica (9.8)1.7%—Cisco Catalyst PON Switch Cgp-ont-1p FirmwareCisco Catalyst PON Switch Cgp-ont-4p FirmwareCisco Catalyst PON Switch Cgp-ont-4pvc FirmwareCisco Catalyst PON Switch Cgp-ont-4tvcw Firmware+14/11/202117/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform…
ModificadaAlta (7.5)0.83%—Freeswitch26/10/202117/6/2026
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, an attacker can perform a SIP digest leak attack against FreeSWITCH and receive the challenge response of a…
ModificadaMedia (5.3)1.7%—Freeswitch26/10/202117/6/2026
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. By default, SIP requests of the type SUBSCRIBE are not authenticated in the affected versions of FreeSWITCH. Abuse of this security…