Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Arista EOS | 16/4/2020 | 17/6/2026 | An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in… | |
| Modificada | Alta (8.8) | 1.8% | 💥 Exploit | Oracle Solaris | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While… | |
| Modificada | Alta (7.8) | 0.36% | — | Oracle Solaris | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While… | |
| Modificada | Alta (7.8) | 0.56% | — | Oracle Solaris | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While… | |
| Modificada | Baja (2.5) | 0.54% | — | Oracle Solaris | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Whodo). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require… | |
| Modificada | Baja (2.5) | 0.55% | — | Oracle Solaris | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: SMF command svcbundle). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful… | |
| Modificada | Media (6.1) | 0.61% | — | Firmware Analysis AND Comparison Tool Project Firmware Analysis AND Comparison Tool | 2/4/2020 | 17/6/2026 | Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py. | |
| Modificada | Crítica (9.8) | 4.0% | — | TwistedFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+2 | 12/3/2020 | 17/6/2026 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request. | |
| Analizada | Alta (7.8) | 1.4% | ⚠ Explotación activa💥 PoC | Google AndroidHuawei Berkeley-l09 FirmwareHuawei Columbia-al10b FirmwareHuawei Columbia-l29d Firmware+25 | 10/3/2020 | 17/6/2026 | In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | |
| Modificada | Crítica (9.8) | 74% | — | Netkit Telnet Project Netkit TelnetFedoraproject FedoraDebian LinuxArista EOS+2 | 6/3/2020 | 17/6/2026 | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Arista Dcs-7050qx-32s-r FirmwareArista Dcs-7050cx3-32s-r FirmwareArista Dcs-7280sram-48c6-r Firmware | 20/2/2020 | 17/6/2026 | Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character. NOTE: the vendor reports that this is a configuration issue relating to an overly permissive regular… | |
| Modificada | Alta (7.8) | 1.4% | 💥 Exploit | Claris Filemaker PROClaris Filemaker PRO Advanced | 11/2/2020 | 17/6/2026 | An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges. | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Media (6.5) | 3.0% | — | QemuFedoraproject FedoraArista EOS | 23/1/2020 | 17/6/2026 | Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message. | |
| Modificada | Media (6.5) | 2.3% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxArista EOS | 23/1/2020 | 17/6/2026 | The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets. | |
| Modificada | Media (6.5) | 3.6% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+4 | 23/1/2020 | 17/6/2026 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | |
| Modificada | Alta (7.5) | 3.2% | — | WiresharkFedoraproject FedoraOpensuse LeapOracle ZFS Storage Appliance KIT+1 | 16/1/2020 | 17/6/2026 | In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors. | |
| Modificada | Alta (8.8) | 0.64% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the… | |
| Modificada | Media (6) | 0.35% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is… | |
| Modificada | Media (4.6) | 0.39% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require… | |
| Modificada | Media (4.4) | 0.56% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: X Window System). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks… | |
| Modificada | Media (5) | 0.35% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require… | |
| Modificada | Alta (7.1) | 0.38% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this… | |
| Modificada | Media (5.8) | 1.6% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may… | |
| Modificada | Alta (7.5) | 0.40% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Consolidation Infrastructure). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.… |