Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Freeswitch | 25/10/2021 | 17/6/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Denial of Service via SIP flooding. When flooding FreeSWITCH with SIP messages, it… | |
| Modificada | Alta (7.5) | 2.5% | — | Freeswitch | 25/10/2021 | 17/6/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. When handling SRTP calls, FreeSWITCH prior to version 1.10.7 is susceptible to a DoS where calls can be terminated by remote attackers.… | |
| Modificada | Alta (7.5) | 3.8% | 💥 PoC | Freeswitch | 25/10/2021 | 17/6/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing. By default, SIP… | |
| Modificada | Media (6.1) | 0.74% | — | User-agent Switcher AND Manager Project User-agent Switcher AND Manager | 22/10/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in NSK User Agent String Switcher Service v0.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the user agent input field. | |
| Modificada | Alta (7.5) | 1.9% | — | Signalwire Freeswitch | 18/10/2021 | 17/6/2026 | An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value. | |
| Modificada | Alta (7.5) | 1.1% | — | Qnap Qsw-m2116p-2t2s FirmwareQnap Qunetswitch | 10/9/2021 | 17/6/2026 | A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this… | |
| Modificada | Crítica (9.8) | 97% | — | Nagios XI Switch Wizard | 13/8/2021 | 17/6/2026 | Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection). | |
| Modificada | Media (5.5) | 1.2% | — | Openvswitch | 20/7/2021 | 17/6/2026 | Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dell EMC Powerswitch S4112f-onDell EMC Powerswitch S4112t-onDell EMC Powerswitch S4128f-onDell EMC Powerswitch S4128t-on+9 | 19/7/2021 | 17/6/2026 | Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauthenticated malicious user could exploit this vulnerability and gain administrative privileges. | |
| Modificada | Alta (8.1) | 0.64% | — | Sonicwall Switch | 9/7/2021 | 17/6/2026 | Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system instability or potentially read sensitive information from the memory locations. | |
| Modificada | Alta (8.8) | 0.87% | — | Wp-currency Wordpress Currency Switcher | 7/7/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.68% | — | Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+11 | 25/6/2021 | 17/6/2026 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards. | |
| Modificada | Media (6.1) | 0.58% | — | Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+11 | 25/6/2021 | 17/6/2026 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client. | |
| Modificada | Media (5.3) | 0.95% | — | Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+11 | 25/6/2021 | 17/6/2026 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected. | |
| Modificada | Alta (7.5) | 1.6% | — | Hitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io FirmwareHitachienergy Rtu500 Firmware+5 | 14/6/2021 | 17/6/2026 | Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as… | |
| Modificada | Media (6.5) | 0.38% | — | Fortinet Fortiswitch | 1/6/2021 | 17/6/2026 | A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP/EDP packets to the device. | |
| Modificada | Alta (8.8) | 1.3% | — | Wp-buy Login AS User OR Customer (user Switching) | 14/5/2021 | 17/6/2026 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps… | |
| Modificada | Alta (7.5) | 3.2% | — | Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+13 | 18/3/2021 | 17/6/2026 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (8.1) | 0.64% | — | Elementary Switchboard Bluetooth PlugFedoraproject Fedora | 12/3/2021 | 17/6/2026 | Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted, allowing physically proximate attackers… | |
| Modificada | Alta (7.5) | 8.0% | 💥 PoC | OpenvswitchDebian LinuxFedoraproject Fedora | 11/2/2021 | 17/6/2026 | A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to… | |
| Modificada | Alta (8.8) | 1.3% | — | HPE KVM IP Console Switch G2 Firmware | 2/10/2020 | 17/6/2026 | A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3. | |
| Modificada | Media (5.4) | 0.52% | — | HPE KVM IP Console Switch G2 Firmware | 2/10/2020 | 17/6/2026 | A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3. | |
| Modificada | Baja (3.7) | 4.9% | — | OpensslCanonical Ubuntu LinuxDebian LinuxOracle JD Edwards World Security+11 | 9/9/2020 | 17/6/2026 | The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent… | |
| Modificada | Alta (8.8) | 4.4% | — | UI Edgeswitch FirmwareOpensuse Backports SLEOpensuse Leap | 17/8/2020 | 17/6/2026 | A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges. | |
| Modificada | Media (6.5) | 1.7% | — | UI Edgeswitch Firmware | 17/8/2020 | 17/6/2026 | An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages. |