Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Broadcom CA Automic Automation16/6/202217/6/2026
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.
ModificadaAlta (7.5)1.2%—Broadcom CA Clarity16/6/202217/6/2026
CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could allow a remote attacker to potentially view the contents of any file on the system.
ModificadaBaja (3.3)0.16%—Broadcom Sannav9/5/202217/6/2026
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
ModificadaAlta (8.8)1.2%—Broadcom Sannav6/5/202217/6/2026
A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they should not be able to access and perform actions that they should not be able to perform. The vulnerability exists because restrictions…
ModificadaMedia (6.5)0.29%—Broadcom Sannav6/5/202217/6/2026
Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt stored account passwords.
ModificadaCrítica (9.8)0.94%—Broadcom Sannav6/5/202217/6/2026
In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.
ModificadaAlta (7.5)2.0%—Broadcom TcpreplayFedoraproject Fedora4/5/202217/6/2026
Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.
ModificadaAlta (7.8)0.85%—Broadcom Tcpreplay12/4/202217/6/2026
Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c.
ModificadaAlta (7.8)0.84%—Broadcom Tcpreplay12/4/202217/6/2026
Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free.
ModificadaMedia (6.1)0.72%—Broadcom Symantec Siteminder28/3/202216/6/2026
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.8)1.1%—Broadcom TcpreplayFedoraproject Fedora26/3/202217/6/2026
tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
ModificadaAlta (7.8)1.1%—Broadcom TcpreplayFedoraproject Fedora26/3/202217/6/2026
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.
ModificadaAlta (7.8)1.1%—Broadcom TcpreplayFedoraproject Fedora26/3/202217/6/2026
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
ModificadaMedia (5.5)1.0%—Broadcom TcpreplayFedoraproject Fedora26/3/202217/6/2026
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
ModificadaAlta (7.8)0.54%—Linux KernelOracle Communications Cloud Native Core Binding Support FunctionDebian LinuxBroadcom Brocade Fabric Operating System Firmware+523/3/202217/6/2026
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control…
ModificadaMedia (5.5)0.61%—Broadcom Tcpreplay22/3/202217/6/2026
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
ModificadaMedia (6.5)0.82%—Broadcom Fabric Operating System18/3/202217/6/2026
The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An attacker who has compromised the FOS system may utilize this weakness to capture sensitive information, such as user…
ModificadaMedia (6.5)0.70%—Broadcom Fabric Operating System18/3/202217/6/2026
A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files.
ModificadaCrítica (9.8)1.3%—Broadcom Fabric Operating System21/2/202217/6/2026
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.
ModificadaMedia (6.5)0.91%—Broadcom Fabric Operating System21/2/202217/6/2026
A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “factory” account, to read the contents of any file on the filesystem utilizing one of a few available binaries.
ModificadaMedia (6.1)0.72%—Broadcom Layer7 API Management Oauth Toolkit18/2/202217/6/2026
A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attacks or other social engineering techniques. A successful attack allows injecting malicious code into…
ModificadaCrítica (9.8)2.4%—Broadcom Xcom Data Transport14/2/202217/6/2026
XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges.
ModificadaMedia (5.5)0.71%—Broadcom Tcpreplay11/2/202217/6/2026
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.
ModificadaMedia (5.5)0.71%—Broadcom Tcpreplay11/2/202217/6/2026
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c
ModificadaAlta (8.8)1.3%—Broadcom CA Harvest Software Change Manager4/2/202217/6/2026
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.
Orbitaley — Vulnerabilidades