Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 1.1% | — | Cisco Cgr1000 Compute ModuleCisco Ic3000 Industrial Compute GatewayCisco Ir510 Operating SystemCisco IOS+1 | 15/4/2022 | 17/6/2026 | Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or… | |
| Modificada | Media (4.8) | 0.64% | — | Cisco Cgr1000 Compute ModuleCisco Ic3000 Industrial Compute GatewayCisco Ir510 Operating SystemCisco IOS+1 | 15/4/2022 | 17/6/2026 | Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or… | |
| Modificada | Alta (7.8) | 0.54% | — | Linux KernelOracle Communications Cloud Native Core Binding Support FunctionDebian LinuxBroadcom Brocade Fabric Operating System Firmware+5 | 23/3/2022 | 17/6/2026 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control… | |
| Modificada | Media (6.5) | 0.82% | — | Broadcom Fabric Operating System | 18/3/2022 | 17/6/2026 | The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An attacker who has compromised the FOS system may utilize this weakness to capture sensitive information, such as user… | |
| Modificada | Media (6.5) | 0.70% | — | Broadcom Fabric Operating System | 18/3/2022 | 17/6/2026 | A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files. | |
| Modificada | Media (4.3) | 3.3% | — | Cisco Firepower Extensible Operating SystemCisco Nx-os | 23/2/2022 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol… | |
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Fabric Operating System | 21/2/2022 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system. | |
| Modificada | Media (6.5) | 0.91% | — | Broadcom Fabric Operating System | 21/2/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “factory” account, to read the contents of any file on the filesystem utilizing one of a few available binaries. | |
| Analizada | Alta (7.5) | 3.6% | 💥 PoC | Linux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+22 | 25/12/2021 | 5/8/2026 | In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses. | |
| Modificada | Alta (8.8) | 0.78% | — | Browser AND Operating System Finder Project Browser AND Operating System Finder | 1/12/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors. | |
| Modificada | Baja (3.3) | 1.4% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Information Disclosure Vulnerability | |
| Modificada | Media (6.8) | 0.69% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Elevation of Privilege Vulnerability | |
| Modificada | Media (6.8) | 0.86% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Elevation of Privilege Vulnerability | |
| Modificada | Media (6.8) | 0.69% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Elevation of Privilege Vulnerability | |
| Modificada | Media (5.5) | 1.6% | — | Microsoft Azure Real Time Operating System | 10/11/2021 | 19/8/2026 | Azure RTOS Information Disclosure Vulnerability | |
| Modificada | Alta (7.4) | 0.39% | — | Cisco FxosCisco Firepower Extensible Operating SystemCisco IOSCisco IOS XE+2 | 23/9/2021 | 17/6/2026 | A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input… | |
| Modificada | Media (6.8) | 0.69% | — | TI 15.4-stackTI Ble5-stackDynamic Multi-protocal ManagerTI Easylink+3 | 20/9/2021 | 17/6/2026 | TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Alta (7.5) | 63% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+9 | 16/9/2021 | 17/6/2026 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). | |
| Modificada | Alta (7.5) | 65% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+14 | 16/9/2021 | 17/6/2026 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (5.5) | 0.21% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x train All releases in the MOS-0.2x train… | |
| Modificada | Alta (7.8) | 0.22% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and post releases in the MOS-0.1x train… | |
| Modificada | Alta (7.8) | 0.23% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train… | |
| Modificada | Crítica (9.8) | 0.93% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post… | |
| Modificada | Alta (8.8) | 0.88% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releases |