Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
931 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute | |
| Modificada | Alta (7.5) | 0.59% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux | |
| Modificada | Alta (7.5) | 0.60% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller Web server (nginx) is serving private files without any authentication | |
| Modificada | Media (5.5) | 0.12% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server | |
| Modificada | Alta (7.5) | 0.59% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file | |
| Modificada | Alta (7.5) | 0.35% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux | |
| Modificada | Alta (7.5) | 0.40% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers | |
| Modificada | Crítica (9.8) | 0.71% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup | |
| Modificada | Media (6.5) | 0.58% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user | |
| Modificada | Alta (7.5) | 0.64% | — | Siemens Ruggedcom ROS | 8/8/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M2200NC, RUGGEDCOM M969, RUGGEDCOM M969F,… | |
| Modificada | Alta (7.5) | 0.54% | — | Siemens Ruggedcom Crossbow | 8/8/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file write messages. An unauthenticated remote attacker could write arbitrary files to the affected application's file system. | |
| Modificada | Crítica (9.8) | 0.94% | — | Siemens Ruggedcom Crossbow | 8/8/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database. | |
| Modificada | Alta (8.8) | 0.80% | — | Siemens Ruggedcom Crossbow | 8/8/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an authenticated remote attackers to execute arbitrary SQL queries on the server database and escalate privileges. | |
| Modificada | Crítica (9.8) | 0.69% | — | Siemens Ruggedcom ROS | 8/8/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M2200NC, RUGGEDCOM M969, RUGGEDCOM M969F,… | |
| Modificada | Crítica (9.8) | 0.62% | — | Ai-dev Aioptimizedcombinations | 3/8/2023 | 17/6/2026 | ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. | |
| Modificada | Media (5.3) | 0.64% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface. | |
| Modificada | Alta (7.1) | 0.16% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0. | |
| Modificada | Media (6.1) | 0.48% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application. |