Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.33%—Omron Cx-flnetOmron Cx-oneOmron Cx-programmerOmron Cx-protocol+317/4/201817/6/2026
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box…
ModificadaAlta (7.8)0.32%—Omron Cx-flnetOmron Cx-oneOmron Cx-programmerOmron Cx-protocol+317/4/201817/6/2026
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box…
ModificadaAlta (7.7)1.6%—Cisco Small Business 500 Series Stackable Managed Switches Firmware8/3/201817/6/2026
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be…
ModificadaMedia (5.5)0.58%—HP Officeconnect 1820 8G Switch J9979a FirmwareHP Officeconnect 1820 24G Poe+ (185w) Switch J9983a FirmwareHP Officeconnect 1820 24G Switch J9980a FirmwareHP Officeconnect 1820 48G Poe+ (370w) Switch J9984a Firmware+215/2/201817/6/2026
A local Unauthorized Data Modification vulnerability in HPE OfficeConnect Network Switches version PT.02.01 including PT.01.03 through PT.01.14
ModificadaMedia (6.1)1.5%—Ipswitch Moveit2/2/201817/6/2026
Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. Attackers can leverage this vulnerability to send malicious messages to other users in order to steal session cookies and launch client-side attacks.
ModificadaCrítica (9.8)3.1%—Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+2512/1/201817/6/2026
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain…
ModificadaMedia (5.3)1.2%—Phoenixcontact FL Switch 3005 FirmwarePhoenixcontact FL Switch 3005t FirmwarePhoenixcontact FL Switch 3004t-fx FirmwarePhoenixcontact FL Switch 3004t-fx ST Firmware+2512/1/201817/6/2026
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information.
ModificadaMedia (5.7)0.70%—Cisco Nx-osCisco LAN Switch Software30/11/201717/6/2026
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this vulnerability by injecting crafted command…
ModificadaMedia (6)0.38%—Cisco Nx-osCisco Unified Computing SystemCisco LAN Switch Software30/11/201717/6/2026
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted command on the CLI. An…
ModificadaAlta (7.8)2.2%💥 ExploitIpswitch WS FTP3/11/201717/6/2026
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729.
ModificadaCrítica (9.8)2.5%—Ipswitch Imail Server3/10/201717/6/2026
Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETRE or ETCTERARED.
ModificadaCrítica (9.8)2.5%—Ipswitch Imail Server3/10/201717/6/2026
Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETBL or ETCETERABLUE.
ModificadaMedia (5.9)1.2%—Openvswitch2/10/201717/6/2026
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful…
ModificadaMedia (6.5)0.54%—Siemens 7KM PAC Switched Ethernet Profinet Expansion Module Firmware30/8/201717/6/2026
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requires a manual restart via the main device to recover.
ModificadaMedia (4.2)1.7%—Cisco Nx-osCisco Nx-os FOR Nexus 5500 Platform SwitchesCisco Nx-os FOR Nexus 5600 Platform SwitchesCisco Nx-os FOR Nexus 7700 Series Switches+37/8/201717/6/2026
Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an…
ModificadaMedia (5.3)0.95%—Belden Hirschmann Gecko Lite Managed Switch Firmware30/6/201717/6/2026
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously.
ModificadaAlta (7.1)0.44%—Belden Hirschmann Gecko Lite Managed Switch Firmware30/6/201717/6/2026
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.
ModificadaMedia (6.5)0.92%—Belden Hirschmann Gecko Lite Managed Switch Firmware30/6/201717/6/2026
A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server receives a request, but does not sufficiently verify that the request is being sent to the expected destination.
ModificadaMedia (6.5)0.68%—Cisco MDS 9000 Nx-osCisco Nx-os FOR Nexus 5500 Platform SwitchesCisco Nx-os FOR Nexus 5600 Platform SwitchesCisco Nx-os FOR Nexus 7700 Series Switches+113/6/201717/6/2026
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when an FCoE-related process unexpectedly reloads. This vulnerability affects Cisco NX-OS Software on the following…
ModificadaCrítica (9.8)2.8%—Openvswitch29/5/201717/6/2026
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.
ModificadaCrítica (9.8)2.4%—Openvswitch29/5/201717/6/2026
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
ModificadaMedia (6.5)1.0%—Openvswitch29/5/201717/6/2026
In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch.
ModificadaAlta (8.8)0.94%—Openvswitch29/5/201717/6/2026
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch.
ModificadaCrítica (9.8)2.9%—OpenvswitchDebian LinuxRedhat OpenstackRedhat Virtualization+123/5/201717/6/2026
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
ModificadaCrítica (9.8)2.0%—Ipswitch Moveit DMZIpswitch Moveit Transfer 201718/5/201717/6/2026
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.