Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
931 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.7) | 0.70% | — | Cedcommerce Wholesale Market FOR Woocommerce | 2/1/2023 | 17/6/2026 | The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite) | |
| Modificada | Media (4.9) | 0.81% | — | Cedcommerce Wholesale Market FOR Woocommerce | 19/12/2022 | 17/6/2026 | The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not be able to (for example in multisite) | |
| Modificada | Media (6.5) | 0.39% | — | Cedcommerce Smsa Shipping FOR Woocommerce | 19/12/2022 | 17/6/2026 | The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as well as does not validate the file to be downloaded, allowing any authenticated users, such as subscriber to download arbitrary file from the server | |
| Modificada | Alta (7.5) | 0.87% | — | Cedcommerce Wholesale Market FOR Woocommerce | 19/12/2022 | 17/6/2026 | The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server. | |
| Modificada | Alta (8.8) | 0.91% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4 | |
| Modificada | Media (6.7) | 0.94% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4 | |
| Modificada | Media (5.3) | 0.71% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session. | |
| Modificada | Media (5.1) | 0.72% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data. | |
| Modificada | Media (5.2) | 0.27% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords. | |
| Modificada | Alta (7.1) | 0.24% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system. | |
| Modificada | Media (4.9) | 0.47% | — | Broadcom Brocade Sannav | 9/12/2022 | 17/6/2026 | Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information. | |
| Modificada | Crítica (9.8) | 1.6% | — | Broadcom Fabric Operating SystemBrocade Fabric Operating System | 8/12/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address. | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | Broadcom Symantec Endpoint Protection | 1/12/2022 | 17/6/2026 | Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password… | |
| Modificada | Crítica (9.8) | 0.72% | — | Broadcom Symantec Endpoint Protection | 1/12/2022 | 17/6/2026 | Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. | |
| Modificada | Alta (7.8) | 0.34% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows, allowing arbitrary code execution as the root user account. | |
| Modificada | Alta (7.8) | 0.35% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in fab_seg.c.h libraries of all Brocade Fabric OS versions before Brocade Fabric OS v9.1.1, v9.0.1e, v8.2.3c, v8.2.0_cbn5, 7.4.2j could allow local authenticated attackers to exploit stack-based buffer overflows and execute arbitrary code as the root user account. | |
| Modificada | Alta (8.8) | 1.6% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands. | |
| Modificada | Alta (7.8) | 0.20% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload, license, and “fosexec”. | |
| Modificada | Media (5.5) | 0.22% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands “configshow” and “supportlink”. | |
| Modificada | Media (5.5) | 0.22% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”. | |
| Modificada | Alta (8.8) | 0.19% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges. | |
| Modificada | Alta (7.2) | 1.4% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitrary code on the Brocade switch. | |
| Modificada | Media (6.5) | 0.21% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file. | |
| Modificada | Alta (8.8) | 0.77% | — | Broadcom Fabric Operating System | 25/10/2022 | 17/6/2026 | Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin… | |
| Modificada | Media (4.3) | 0.66% | — | Broadcom Reactor Netty | 19/10/2022 | 4/9/2026 | Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled. |