Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.4% | — | Opendaylight L2switch | 20/3/2017 | 17/6/2026 | hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topology spoofing." | |
| Modificada | Media (5.9) | 1.9% | — | Belden Hirschmann Gecko Lite Managed Switch Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the configuration file, which includes hashes of user passwords, is saved to a location that is accessible without authentication by path traversal. | |
| Modificada | Crítica (9.8) | 4.6% | — | Fortinet Fortiswitch | 9/9/2016 | 17/6/2026 | Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE models, when in… | |
| Modificada | Crítica (9.8) | 4.0% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216. | |
| Modificada | Alta (7.5) | 2.9% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238. | |
| Modificada | Media (6.1) | 1.5% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz76232. | |
| Modificada | Alta (8.8) | 0.97% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Fortinet FortiosFortinet Fortiswitch | 24/8/2016 | 17/6/2026 | Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER. | |
| Modificada | Crítica (9.8) | 6.4% | — | OpenvswitchRedhat Openshift | 3/7/2016 | 17/6/2026 | Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command. | |
| Modificada | Media (5.4) | 1.8% | — | Ipswitch Moveit DMZ | 15/4/2016 | 17/6/2026 | Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files. | |
| Modificada | Media (5.3) | 2.1% | — | Ipswitch Moveit DMZ | 10/2/2016 | 17/6/2026 | Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx. | |
| Modificada | Media (6.1) | 1.4% | — | Ipswitch Moveit Mobile | 10/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/. | |
| Modificada | Alta (8.8) | 0.91% | — | Ipswitch Moveit Mobile | 10/2/2016 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (4.3) | 3.0% | — | Ipswitch Moveit DMZ | 10/2/2016 | 17/6/2026 | The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll. | |
| Modificada | Media (6.5) | 3.1% | — | Ipswitch Moveit DMZIpswitch Moveit Mobile | 10/2/2016 | 17/6/2026 | The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco 500 Series Switch Firmware | 30/1/2016 | 17/6/2026 | The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330. | |
| Modificada | Media (5.3) | 1.3% | — | Cisco 300 Series Managed Switch Firmware | 27/1/2016 | 17/6/2026 | The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174. | |
| Modificada | Alta (8.4) | 0.59% | — | HP Network Switch SoftwareHP J8692aHP J8693aHP J8697a+50 | 5/1/2016 | 17/6/2026 | HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859. | |
| Modificada | Alta (7.8) | 0.48% | — | HP Network Switch Software | 5/1/2016 | 17/6/2026 | HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6860. | |
| Modificada | Media (6.5) | 2.0% | — | Jg786a HP Flexfabric 12500 4-port 100gbe CFP FDJg787a HP Flexfabric 12500 4-port 100gbe CFP FD TAAJg788a HP Flexfabric 12500 4-port 100gbe CFP FGJg789a HP Flexfabric 12500 4-port 100gbe CFP FG TAA+83 | 5/1/2016 | 17/6/2026 | HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and forwarding (VRF) hopping." | |
| Modificada | Alta (10) | 2.3% | — | Loytec L-switch AND L-ip Firmware | 21/12/2015 | 17/6/2026 | LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backup file via unspecified vectors. | |
| Modificada | Alta (7.1) | 1.4% | — | Lenovo Switch CenterIBM System Networking Switch Center | 12/11/2015 | 17/6/2026 | Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read… | |
| Modificada | Media (5) | 1.3% | — | Lenovo Switch CenterIBM System Networking Switch Center | 12/11/2015 | 17/6/2026 | The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password. | |
| Modificada | Alta (7.2) | 0.43% | — | IBM System Networking Switch CenterLenovo Switch Center | 12/11/2015 | 17/6/2026 | The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file. | |
| Modificada | Alta (7.1) | 1.4% | — | IBM System Networking Switch CenterLenovo Switch Center | 12/11/2015 | 17/6/2026 | Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read… |