Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.54% | — | Autoswitch Python Virtualenv Project Autoswitch Python Virtualenv | 13/5/2020 | 17/6/2026 | In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0 | |
| Modificada | Alta (7.5) | 2.4% | — | Fortinet FortianalyzerFortinet Fortiap-sFortinet Fortiap-w2Fortinet Fortimanager+1 | 7/4/2020 | 17/6/2026 | An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces… | |
| Modificada | Alta (7.8) | 0.52% | — | UI Edgeswitch | 7/2/2020 | 17/6/2026 | A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrator (Privilege-15). | |
| Modificada | Media (6.1) | 0.91% | — | Nokia 1830 Photonic Service Switch-4 FirmwareNokia 1830 Photonic Service Switch-16 FirmwareNokia 1830 Photonic Service Switch-32 Firmware | 31/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html. | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Belkin Wemo Switch Firmware | 28/1/2020 | 16/6/2026 | Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. | |
| Modificada | Alta (7.8) | 0.51% | — | Belkin Wemo Insight Switch Firmware | 27/1/2020 | 17/6/2026 | A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions. | |
| Modificada | Alta (8.8) | 1.7% | — | Bigswitch BIG Cloud FabricBigswitch BIG Monitoring FabricBigswitch Multi-cloud Director | 24/1/2020 | 17/6/2026 | An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. A read-only user can access sensitive… | |
| Modificada | Media (6.1) | 1.0% | — | Bigswitch BIG Cloud FabricBigswitch BIG Monitoring FabricBigswitch Multi-cloud Director | 24/1/2020 | 17/6/2026 | An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. An unauthenticated attacker may inject… | |
| Modificada | Crítica (9.8) | 29% | 💥 Exploit | Freeswitch | 2/12/2019 | 17/6/2026 | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. | |
| Modificada | Media (6.7) | 0.38% | 💥 PoC | Nvidia GpumodeswitchNvidia NvflashNvidia Nvuflash | 18/11/2019 | 17/6/2026 | NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not… | |
| Modificada | Media (6.5) | 1.8% | — | Wpwham Currency Switcher FOR Woocommerce | 2/11/2019 | 17/6/2026 | An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an… | |
| Modificada | Crítica (9.8) | 1.5% | — | Ipswitch Moveit Transfer | 31/10/2019 | 17/6/2026 | In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used. | |
| Modificada | Crítica (9.8) | 1.9% | — | Ipswitch Moveit Transfer | 31/10/2019 | 17/6/2026 | In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine… | |
| Modificada | Alta (7.5) | 1.6% | — | Belkin Wemo Switch 28B Firmware | 12/10/2019 | 17/6/2026 | An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs. | |
| Modificada | Crítica (9.4) | 5.2% | 💥 Exploit | Ipswitch Moveit Transfer | 24/9/2019 | 17/6/2026 | MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to… | |
| Modificada | Alta (7.2) | 2.7% | — | UI Edgeswitch Firmware | 10/7/2019 | 17/6/2026 | Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root. | |
| Modificada | Media (4.9) | 1.3% | — | UI Edgeswitch Firmware | 10/7/2019 | 17/6/2026 | DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands. | |
| Modificada | Crítica (9.1) | 4.0% | — | Ipswitch WS FTP Server | 11/6/2019 | 17/6/2026 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a flaw in the SCP listener by crafting strings using specific patterns to write files and create directories outside of their authorized directory. | |
| Modificada | Alta (7.5) | 4.7% | — | Ipswitch WS FTP Server | 11/6/2019 | 17/6/2026 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose path names on the host operating system. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ipswitch WS FTP Server | 11/6/2019 | 17/6/2026 | An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a path traversal vulnerability using the SCP protocol. Attackers who leverage this flaw could also obtain remote code execution by crafting a payload that abuses the SITE command… | |
| Modificada | Alta (7.5) | 2.2% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections. | |
| Modificada | Alta (8.8) | 0.86% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default. | |
| Modificada | Media (5.3) | 1.6% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 7/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images. | |
| Modificada | Crítica (9.8) | 2.3% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 6/5/2019 | 17/6/2026 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts. |