Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
484 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.86% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Elevation of Privilege Vulnerability | |
| Modificada | Media (6.8) | 0.69% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Elevation of Privilege Vulnerability | |
| Modificada | Media (5.5) | 1.6% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Information Disclosure Vulnerability | |
| Modificada | Alta (7.4) | 0.39% | — | Cisco FxosCisco Firepower Extensible Operating SystemCisco IOSCisco IOS XE+2 | 23/9/2021 | 17/6/2026 | A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input… | |
| Modificada | Media (6.8) | 0.69% | — | TI 15.4-stackTI Ble5-stackDynamic Multi-protocal ManagerTI Easylink+3 | 20/9/2021 | 17/6/2026 | TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Alta (7.5) | 63% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+9 | 16/9/2021 | 17/6/2026 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). | |
| Modificada | Alta (7.5) | 65% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+14 | 16/9/2021 | 17/6/2026 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (5.5) | 0.21% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x train All releases in the MOS-0.2x train… | |
| Modificada | Alta (7.8) | 0.22% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and post releases in the MOS-0.1x train… | |
| Modificada | Alta (7.8) | 0.23% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train… | |
| Modificada | Crítica (9.8) | 0.93% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post… | |
| Modificada | Alta (8.8) | 0.88% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releases | |
| Modificada | Alta (7.8) | 0.22% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior… | |
| Modificada | Alta (7.8) | 0.24% | — | Broadcom Fabric Operating System | 12/8/2021 | 17/6/2026 | A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST. | |
| Modificada | Media (5.3) | 0.91% | — | Broadcom Fabric Operating System | 12/8/2021 | 17/6/2026 | ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch. | |
| Modificada | Alta (7.8) | 0.27% | — | Broadcom Fabric Operating System | 12/8/2021 | 17/6/2026 | The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7.4.2h do not properly handle malformed user input, resulting in a service crash. An authenticated attacker could use this weakness to cause the FOS HTTP application handler to crash, requiring a… | |
| Modificada | Media (5.4) | 0.60% | — | Broadcom Fabric Operating System | 12/8/2021 | 17/6/2026 | The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting in reading memory addresses outside the intended range. An unauthenticated… | |
| Modificada | Alta (7.8) | 0.46% | — | Broadcom Fabric Operating System | 12/8/2021 | 17/6/2026 | The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to process user input. Authenticated attackers can abuse this vulnerability to exploit stack-based buffer overflows, allowing execution of arbitrary code as the root user… | |
| Analizada | Alta (7.8) | 79% | ⚠ Explotación activa💥 Exploit | Netapp C400 FirmwareNetapp C250 FirmwareNetapp H410c FirmwareNetapp H300s Firmware+17 | 7/7/2021 | 17/6/2026 | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space | |
| Modificada | Alta (7.4) | 0.49% | — | Broadcom Brocade SannavBroadcom Fabric Operating System | 9/6/2021 | 17/6/2026 | The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications. | |
| Modificada | Media (5.3) | 0.95% | — | Broadcom Fabric Operating System | 9/6/2021 | 17/6/2026 | Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations. | |
| Modificada | Alta (7.5) | 0.99% | — | Broadcom Fabric Operating System | 9/6/2021 | 17/6/2026 | Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch panic. | |
| Modificada | Media (5.5) | 0.22% | — | Versa-networks Versa AnalyticsVersa-networks Versa DirectorVersa-networks Versa Operating System | 26/5/2021 | 17/6/2026 | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alone are insufficient in thwarting password cracking. Attackers can… | |
| Modificada | Media (5.9) | 0.31% | — | Versa-networks Versa Operating System | 26/5/2021 | 17/6/2026 | In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher suites also violates the Data Protection TSR (Technical Security Requirements). |