Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

931 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)3.1%💥 ExploitBroadcom Symantec Siteminder Webagent30/5/202317/6/2026
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
ModificadaMedia (6.1)0.47%—Broadcom Vmware Nsx-t Data Center26/5/202317/6/2026
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.
ModificadaMedia (5.4)0.46%—Jenkins Loadcomplete Support16/5/202317/6/2026
Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (5.5)1.3%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+730/3/202317/6/2026
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the…
ModificadaMedia (5.9)1.9%—Haxx LibcurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapBroadcom Brocade Fabric Operating System Firmware+530/3/202317/6/2026
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads…
ModificadaAlta (8.8)2.2%—Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerBroadcom Brocade Fabric Operating System Firmware+530/3/202317/6/2026
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw…
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.
ModificadaAlta (7.5)1.4%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.
ModificadaAlta (7.5)1.5%—Broadcom Tcpreplay16/3/202317/6/2026
An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c.
ModificadaAlta (8.8)0.80%—Siemens Ruggedcom Crossbow14/3/202317/6/2026
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database.
ModificadaMedia (4.3)0.52%—Siemens Ruggedcom Crossbow14/3/202317/6/2026
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to access data they are not authorized for.
ModificadaAlta (8.8)0.63%—Siemens Ruggedcom Crossbow14/3/202317/6/2026
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise…
ModificadaAlta (8.8)0.48%—Siemens Ruggedcom Crossbow14/3/202317/6/2026
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.
ModificadaAlta (7.8)1.3%—Trustedcomputinggroup Trusted Platform ModuleMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+828/2/202317/6/2026
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it…
ModificadaMedia (5.5)5.6%—Trustedcomputinggroup Trusted Platform ModuleMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+828/2/202317/6/2026
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
ModificadaAlta (7.5)0.72%—Bdcom 1704-wgl Firmware3/2/202317/6/2026
A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-220101 was…
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
ModificadaMedia (5.4)0.56%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
ModificadaAlta (7.8)0.17%—Broadcom Symantec Endpoint Protection20/1/202317/6/2026
Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated
ModificadaCrítica (9.8)1.8%—Cedcommerce Wholesale Market2/1/202317/6/2026
The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Orbitaley — Vulnerabilidades