Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.99%—Broadcom Sannav9/6/202117/6/2026
Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.
ModificadaAlta (7.5)1.3%—Broadcom Brocade Sannav9/6/202117/6/2026
Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.
ModificadaMedia (5.3)0.79%—Broadcom Sannav9/6/202117/6/2026
The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface.
ModificadaCrítica (9.8)1.2%—Broadcom Sannav9/6/202117/6/2026
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).
ModificadaAlta (7.5)0.99%—Broadcom Fabric Operating System9/6/202117/6/2026
Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch panic.
ModificadaAlta (7.2)0.86%—Broadcom Brocade Sannav9/6/202117/6/2026
Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.
ModificadaAlta (7.5)1.0%—Broadcom Sannav9/6/202117/6/2026
Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.
ModificadaMedia (5.5)0.61%—XENARM Cortex-a72Broadcom Bcm2711Intel Core I7-10700k+49/6/202117/6/2026
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
ModificadaMedia (5.5)0.33%—XENARM Cortex-a72Broadcom Bcm2711Intel Core I7-10700k+49/6/202117/6/2026
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.
ModificadaAlta (7.8)0.61%—Broadcom Rabbitmq Server18/5/202117/6/2026
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
ModificadaMedia (6.1)1.1%—GNU WgetBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+229/4/202117/6/2026
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
AnalizadaAlta (7)0.47%—Linux KernelFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1122/4/202130/7/2026
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list…
ModificadaAlta (7.8)0.22%—Broadcom Vmware Nsx-t Data Center19/4/202117/6/2026
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploitation of this issue may allow attackers with local guest user account to assign privileges higher than their own permission level.
ModificadaBaja (3.7)3.1%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+71/4/202117/6/2026
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server…
ModificadaMedia (5.3)5.3%—Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+81/4/202117/6/2026
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP…
ModificadaMedia (6.3)0.30%—GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+226/3/202117/6/2026
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities…
ModificadaAlta (7.5)1.4%—Broadcom Ehealth26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only…
ModificadaAlta (7.8)0.39%—Broadcom Ehealth26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPATH, to be dynamically linked when the emtgtctl2 executable is run. The code in the library will be executed as the…
ModificadaMedia (5.3)2.6%—Gnome GlibBroadcom Brocade Fabric Operating System FirmwareDebian LinuxFedoraproject Fedora11/3/202117/6/2026
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is…
ModificadaAlta (7.5)3.0%—Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+315/2/202117/6/2026
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
ModificadaAlta (7.5)4.1%—Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+315/2/202117/6/2026
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
ModificadaAlta (7.5)1.2%—Broadcom CA Service Catalog5/1/202117/6/2026
CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition.
ModificadaMedia (5.9)3.6%—GNU GlibcFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp Service Processor+44/1/202117/6/2026
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
ModificadaMedia (5.5)1.3%—GNU BinutilsRedhat Enterprise LinuxNetapp HCI Compute Node FirmwareNetapp Cloud Backup+44/1/202117/6/2026
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
ModificadaMedia (5.5)1.2%—GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+44/1/202117/6/2026
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
Orbitaley — Vulnerabilidades