Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
714 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.29% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 22/11/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate. | |
| Modificada | Alta (7.8) | 0.28% | — | Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 21/11/2023 | 17/6/2026 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution. | |
| Modificada | Alta (7.8) | 0.28% | — | Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 20/11/2023 | 17/6/2026 | Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an integer overflow vulnerability in 'HeapTrack_alloc' and result in code execution. | |
| Modificada | Alta (7.8) | 0.28% | — | Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 20/11/2023 | 17/6/2026 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution. | |
| Modificada | Alta (8.8) | 0.31% | — | Danielpowney Multi Rating | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions. | |
| Modificada | Media (4.8) | 0.32% | — | Pixelgrade Comments Rating | 6/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions. | |
| Modificada | Media (6.5) | 0.44% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerability by authenticating to the device CLI and issuing certain commands. | |
| Modificada | Alta (7.5) | 0.47% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server. | |
| Modificada | Media (5.4) | 0.29% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can exploit these issues to obtain escalated privileges. | |
| Modificada | Alta (8.8) | 0.21% | — | Pixelgrade Comments Rating | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions. | |
| Modificada | Media (4.4) | 0.27% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command. | |
| Analizada | Media (4.4) | 0.17% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg --set -expire -minDiff“. | |
| Modificada | Alta (7.5) | 0.36% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS. | |
| Modificada | Alta (7.5) | 0.89% | — | Nokia Service Router LinuxNokia Service Router Operating System | 29/8/2023 | 17/6/2026 | Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes. | |
| Modificada | Media (6) | 0.18% | — | Cisco Firepower Extensible Operating System | 23/8/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker… | |
| Modificada | Crítica (9.8) | 32% | 💥 Exploit | Terra-master Terramaster Operating System | 20/8/2023 | 17/6/2026 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials… | |
| Modificada | Media (4.8) | 0.37% | — | Danielpowney Multi Rating | 18/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions. | |
| Modificada | Media (5.3) | 0.64% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface. | |
| Modificada | Alta (7.1) | 0.16% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0. | |
| Modificada | Media (6.1) | 0.48% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application. | |
| Modificada | Alta (7.8) | 0.17% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0. | |
| Modificada | Media (5.5) | 0.28% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service. | |
| Modificada | Media (5.5) | 0.28% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service. | |
| Modificada | Media (5.5) | 0.18% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep. |