Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

484 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.4%—Linux KernelOpensuse LeapRedhat Enterprise LinuxNetapp Active IQ Unified Manager+137/11/201917/6/2026
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other…
ModificadaMedia (5.5)0.33%—Cisco Firepower Extensible Operating SystemCisco Nx-os5/11/201917/6/2026
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The…
ModificadaAlta (7)0.99%💥 PoCLinux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+144/11/201917/6/2026
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this…
ModificadaMedia (5.9)0.67%—Arista Extensible Operating System10/10/201917/6/2026
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on route updates and in turn potentially…
ModificadaMedia (6.5)1.9%—Cisco Firepower 9300 FirmwareCisco Firepower Extensible Operating SystemCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense2/10/201911/8/2026
A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The…
ModificadaAlta (7.8)0.91%—Cisco Firepower 9300 FirmwareCisco Secure Firewall Threat DefenseCisco Firepower Extensible Operating System2/10/201911/8/2026
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could…
ModificadaCrítica (9.8)1.7%—Linuxfoundation Open Network Operating System22/7/201917/6/2026
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: network connectivity.
ModificadaCrítica (9.8)3.6%—Linuxfoundation Open Network Operating System19/7/201917/6/2026
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java. The attack vector is:…
ModificadaMedia (4.9)1.1%—Linuxfoundation Open Network Operating System18/7/201917/6/2026
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management…
ModificadaMedia (4.9)1.1%—Linuxfoundation Open Network Operating System18/7/201917/6/2026
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is:…
ModificadaMedia (4.9)1.1%—Linuxfoundation Open Network Operating System18/7/201917/6/2026
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is:…
ModificadaMedia (6.7)0.45%—Cisco Nx-osCisco Firepower Extensible Operating System16/5/201917/6/2026
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of…
ModificadaAlta (8.6)2.4%—Cisco Nx-osCisco Firepower Extensible Operating SystemCisco Fx-os16/5/201917/6/2026
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly. The vulnerability is…
ModificadaMedia (6.7)0.48%—Cisco Nx-osCisco Firepower Extensible Operating System15/5/201917/6/2026
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI…
ModificadaMedia (6.7)0.45%—Cisco Firepower Extensible Operating SystemCisco Nx-os15/5/201917/6/2026
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI…
ModificadaMedia (4.4)0.38%—Cisco Firepower Extensible Operating SystemCisco Nx-os7/3/201917/6/2026
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An…
ModificadaAlta (7.5)2.5%—Cisco Firepower Extensible Operating SystemCisco Nx-os7/3/201917/6/2026
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due…
ModificadaAlta (7.5)2.5%—Cisco Firepower Extensible Operating SystemCisco Nx-os7/3/201917/6/2026
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due…
ModificadaCrítica (9.1)2.2%—Broadcom Fabric Operating System3/12/201817/6/2026
A vulnerability in the proxy service of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote unauthenticated attackers to obtain sensitive information and possibly cause a denial of service attack.
ModificadaAlta (7.8)0.35%—Broadcom Fabric Operating System3/12/201817/6/2026
A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
ModificadaAlta (8.8)5.2%—Terra-master Terramaster Operating System27/11/201817/6/2026
System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.
ModificadaMedia (5.3)17%—Terra-master Terramaster Operating System27/11/201817/6/2026
User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.
ModificadaMedia (6.1)1.3%—Terra-master Terramaster Operating System27/11/201817/6/2026
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.
ModificadaAlta (8.8)20%—Terra-master Terramaster Operating System27/11/201817/6/2026
Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.
ModificadaAlta (8.8)25%—Terra-master Terramaster Operating System27/11/201817/6/2026
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.
Orbitaley — Vulnerabilidades