Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Freeswitch25/10/202117/6/2026
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Denial of Service via SIP flooding. When flooding FreeSWITCH with SIP messages, it…
ModificadaAlta (7.5)2.5%—Freeswitch25/10/202117/6/2026
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. When handling SRTP calls, FreeSWITCH prior to version 1.10.7 is susceptible to a DoS where calls can be terminated by remote attackers.…
ModificadaAlta (7.5)3.8%💥 PoCFreeswitch25/10/202117/6/2026
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing. By default, SIP…
ModificadaMedia (6.1)0.74%—User-agent Switcher AND Manager Project User-agent Switcher AND Manager22/10/202117/6/2026
A cross-site scripting (XSS) vulnerability in NSK User Agent String Switcher Service v0.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the user agent input field.
ModificadaAlta (7.5)1.9%—Signalwire Freeswitch18/10/202117/6/2026
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value.
ModificadaAlta (7.5)1.1%—Qnap Qsw-m2116p-2t2s FirmwareQnap Qunetswitch10/9/202117/6/2026
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this…
ModificadaCrítica (9.8)97%—Nagios XI Switch Wizard13/8/202117/6/2026
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
ModificadaMedia (5.5)1.2%—Openvswitch20/7/202117/6/2026
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.
ModificadaCrítica (9.8)1.2%—Dell EMC Powerswitch S4112f-onDell EMC Powerswitch S4112t-onDell EMC Powerswitch S4128f-onDell EMC Powerswitch S4128t-on+919/7/202117/6/2026
Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauthenticated malicious user could exploit this vulnerability and gain administrative privileges.
ModificadaAlta (8.1)0.64%—Sonicwall Switch9/7/202117/6/2026
Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system instability or potentially read sensitive information from the memory locations.
ModificadaAlta (8.8)0.87%—Wp-currency Wordpress Currency Switcher7/7/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (7.5)0.68%—Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+1125/6/202117/6/2026
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.
ModificadaMedia (6.1)0.58%—Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+1125/6/202117/6/2026
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.
ModificadaMedia (5.3)0.95%—Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+1125/6/202117/6/2026
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.
ModificadaAlta (7.5)1.6%—Hitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io FirmwareHitachienergy Rtu500 Firmware+514/6/202117/6/2026
Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as…
ModificadaMedia (6.5)0.38%—Fortinet Fortiswitch1/6/202117/6/2026
A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP/EDP packets to the device.
ModificadaAlta (8.8)1.3%—Wp-buy Login AS User OR Customer (user Switching)14/5/202117/6/2026
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps…
ModificadaAlta (7.5)3.2%—Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+1318/3/202117/6/2026
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
ModificadaAlta (8.1)0.64%—Elementary Switchboard Bluetooth PlugFedoraproject Fedora12/3/202117/6/2026
Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted, allowing physically proximate attackers…
ModificadaAlta (7.5)8.0%💥 PoCOpenvswitchDebian LinuxFedoraproject Fedora11/2/202117/6/2026
A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to…
ModificadaAlta (8.8)1.3%—HPE KVM IP Console Switch G2 Firmware2/10/202017/6/2026
A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
ModificadaMedia (5.4)0.52%—HPE KVM IP Console Switch G2 Firmware2/10/202017/6/2026
A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
ModificadaBaja (3.7)4.9%—OpensslCanonical Ubuntu LinuxDebian LinuxOracle JD Edwards World Security+119/9/202017/6/2026
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent…
ModificadaAlta (8.8)4.4%—UI Edgeswitch FirmwareOpensuse Backports SLEOpensuse Leap17/8/202017/6/2026
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
ModificadaMedia (6.5)1.7%—UI Edgeswitch Firmware17/8/202017/6/2026
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.