Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

484 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.38%—Cisco Firepower Extensible Operating System21/10/202017/6/2026
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating…
ModificadaMedia (6.7)0.40%—Cisco Firepower Extensible Operating SystemCisco Adaptive Security Appliance SoftwareCisco Firepower Threat Defense21/10/202017/6/2026
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating…
ModificadaAlta (8.8)0.56%—Cisco Firepower Extensible Operating System21/10/202017/6/2026
A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker…
ModificadaAlta (7.8)0.35%—Cisco Firepower Extensible Operating System21/10/202017/6/2026
A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms. The vulnerability is due to insufficient protections of the secure boot process. An attacker could exploit this vulnerability by injecting code into a specific file that…
ModificadaCrítica (9.8)2.2%—Lenovo Cloud Networking Operating System14/10/202017/6/2026
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and…
ModificadaCrítica (9.8)1.2%—Broadcom Fabric Operating System25/9/202017/6/2026
Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.
ModificadaCrítica (9.8)2.4%—Broadcom Fabric Operating System25/9/202017/6/2026
Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated attackers to perform various attacks.
ModificadaMedia (5.5)0.34%—Broadcom Fabric Operating System25/9/202017/6/2026
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging.
ModificadaCrítica (9.8)1.3%—Broadcom Fabric Operating System25/9/202017/6/2026
Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability.
ModificadaMedia (6.5)1.0%—Broadcom Fabric Operating System25/9/202017/6/2026
Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files.
ModificadaAlta (8.8)1.0%—Broadcom Fabric Operating System25/9/202017/6/2026
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.
ModificadaMedia (6.1)0.77%—Broadcom Fabric Operating System25/9/202017/6/2026
Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers
ModificadaAlta (7.5)1.4%—Broadcom Fabric Operating System25/9/202017/6/2026
A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.
ModificadaMedia (5.4)0.51%—Broadcom Fabric Operating System25/9/202017/6/2026
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account.
ModificadaMedia (6.7)0.39%—Cisco Firepower Extensible Operating System4/9/202017/6/2026
A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrative credentials to cause a buffer overflow condition. The vulnerability is due to incorrect bounds checking of values that are parsed from a specific file. An attacker could exploit this vulnerability by supplying a…
ModificadaAlta (8.6)1.4%—Cisco Firepower Extensible Operating SystemCisco Nx-os27/8/202017/6/2026
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or…
ModificadaBaja (3.3)0.27%—Cisco Firepower Extensible Operating SystemCisco Nx-os27/8/202017/6/2026
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability…
ModificadaAlta (8.8)2.0%—Openrobotics Robot Operating System20/8/202017/6/2026
Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core package of actionlib, an attacker with…
AnalizadaAlta (7.4)13%💥 PoCOpenbsd OpensshNetapp A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+524/7/202017/6/2026
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking…
ModificadaMedia (6.5)2.0%—Gnome BalsaGnome Glib-networkingCanonical Ubuntu LinuxFedoraproject Fedora+228/5/202017/6/2026
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications…
ModificadaMedia (5.5)0.57%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+827/5/202017/6/2026
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
ModificadaMedia (5.5)0.62%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1427/5/202017/6/2026
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
ModificadaAlta (7)1.0%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1527/5/202017/6/2026
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
ModificadaAlta (7.5)4.4%—OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1428/4/202017/6/2026
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
ModificadaAlta (7.5)53%💥 PoCOpensslDebian LinuxFreebsdFedoraproject Fedora+2221/4/202017/6/2026
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from…
Orbitaley — Vulnerabilidades