Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.81% | — | UI Edgeswitch X | 10/4/2019 | 17/6/2026 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the… | |
| Modificada | Alta (8.8) | 1.9% | — | UI Edgeswitch X | 10/4/2019 | 17/6/2026 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root. | |
| Modificada | Alta (8.8) | 1.9% | — | UI Edgeswitch X | 10/4/2019 | 17/6/2026 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user. | |
| Modificada | Alta (7.5) | 2.7% | 💥 PoC | Freeswitch | 6/12/2018 | 17/6/2026 | FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as demonstrated by an api/system?calc URI. This can also be exploited via CSRF. Alternatively, the… | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Switchvpn | 30/11/2018 | 17/6/2026 | A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-permissive configuration settings and a SUID binary, an attacker is able to execute arbitrary binaries as root. | |
| Modificada | Crítica (9.8) | 1.4% | — | IBM Qlogic 4 GB Fibre Channel Expansion Card FirmwareIBM Qlogic 20-port 4/8 GB SAN Switch Module Firmware | 10/10/2018 | 17/6/2026 | The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password. | |
| Modificada | Media (4.9) | 2.0% | — | OpenvswitchRedhat OpenstackCanonical Ubuntu LinuxDebian Linux | 19/9/2018 | 17/6/2026 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding. | |
| Modificada | Alta (7.5) | 2.5% | — | OpenvswitchRedhat OpenstackCanonical Ubuntu Linux | 19/9/2018 | 17/6/2026 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to… | |
| Modificada | Media (4.3) | 1.9% | — | OpenvswitchRedhat OpenstackCanonical Ubuntu LinuxDebian Linux | 19/9/2018 | 17/6/2026 | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier,… | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | UI Airmax AC FirmwareUI Airmax M XM FirmwareUI Airmax M XW FirmwareUI Airmax M TI Firmware+8 | 5/9/2018 | 17/6/2026 | The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in… | |
| Modificada | Alta (8.8) | 1.0% | — | Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+2 | 30/8/2018 | 17/6/2026 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure… | |
| Modificada | Media (6.5) | 0.79% | — | Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+2 | 30/8/2018 | 17/6/2026 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. Devices did not authenticate themselves to the cloud in device to cloud communication.… | |
| Modificada | Alta (8.1) | 0.86% | — | Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+2 | 30/8/2018 | 17/6/2026 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The process of registering a device with a cloud account was based on an activation code… | |
| Modificada | Crítica (9.8) | 1.6% | — | Mystrom Wifi Switch Firmware | 30/8/2018 | 17/6/2026 | myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers were able to run operating system commands on the device. | |
| Modificada | Alta (8.1) | 0.76% | — | Mystrom Wifi Switch FirmwareMystrom Wifi Button Plus FirmwareMystrom Wifi Button FirmwareMystrom Wifi Switch EU Firmware+2 | 30/8/2018 | 17/6/2026 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by… | |
| Modificada | Media (5.5) | 0.51% | — | HP Officeconnect 1810-24g Switch FirmwareHP Officeconnect 1810-48g Switch FirmwareHP Officeconnect 1810-8 V2 Switch Firmware | 14/8/2018 | 17/6/2026 | A potential security vulnerability has been identified in HPE OfficeConnect 1810 Switch Series (HP 1810-24G - P.2.22 and previous versions, HP 1810-48G PK.1.34 and previous versions, HP 1810-8 v2 P.2.22 and previous versions). The vulnerability could allow local disclosure of sensitive information. | |
| Modificada | Alta (7.2) | 1.9% | — | Ubnt Edgeswitch Firmware | 20/6/2018 | 17/6/2026 | Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater than administrators themselves are allowed. An attacker with access to an admin account could escape… | |
| Modificada | Alta (7.2) | 1.7% | — | UI Edgeswitch Firmware | 20/6/2018 | 17/6/2026 | Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater than administrators themselves are allowed. An attacker with access to an admin account could… | |
| Modificada | Crítica (9) | 2.7% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728). | |
| Modificada | Crítica (9.1) | 4.5% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection. | |
| Modificada | Media (5.3) | 1.9% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user. | |
| Modificada | Alta (8.1) | 2.2% | — | Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+25 | 17/5/2018 | 17/6/2026 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731). | |
| Modificada | Crítica (10) | 1.6% | — | Redlion Sixnet-managed Industrial Switches FirmwareRedlion Stride-managed Ethernet Switches Firmware | 9/5/2018 | 17/6/2026 | A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190. Vulnerable versions of Stride-Managed Ethernet switches and Sixnet-Managed Industrial switches use… | |
| Modificada | Crítica (9.8) | 3.8% | — | OpenslpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+34 | 23/4/2018 | 17/6/2026 | OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability. | |
| Modificada | Alta (7.8) | 0.32% | — | Omron Cx-flnetOmron Cx-oneOmron Cx-programmerOmron Cx-protocol+3 | 17/4/2018 | 17/6/2026 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box… |