Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.4%—Opendaylight L2switch20/3/201717/6/2026
hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topology spoofing."
ModificadaMedia (5.9)1.9%—Belden Hirschmann Gecko Lite Managed Switch Firmware13/2/201717/6/2026
An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the configuration file, which includes hashes of user passwords, is saved to a location that is accessible without authentication by path traversal.
ModificadaCrítica (9.8)4.6%—Fortinet Fortiswitch9/9/201617/6/2026
Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE models, when in…
ModificadaCrítica (9.8)4.0%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216.
ModificadaAlta (7.5)2.9%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238.
ModificadaMedia (6.1)1.5%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz76232.
ModificadaAlta (8.8)0.97%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230.
ModificadaCrítica (9.8)50%💥 ExploitFortinet FortiosFortinet Fortiswitch24/8/201617/6/2026
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.
ModificadaCrítica (9.8)6.4%—OpenvswitchRedhat Openshift3/7/201617/6/2026
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
ModificadaMedia (5.4)1.8%—Ipswitch Moveit DMZ15/4/201617/6/2026
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.
ModificadaMedia (5.3)2.1%—Ipswitch Moveit DMZ10/2/201617/6/2026
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
ModificadaMedia (6.1)1.4%—Ipswitch Moveit Mobile10/2/201617/6/2026
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.
ModificadaAlta (8.8)0.91%—Ipswitch Moveit Mobile10/2/201617/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (4.3)3.0%—Ipswitch Moveit DMZ10/2/201617/6/2026
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
ModificadaMedia (6.5)3.1%—Ipswitch Moveit DMZIpswitch Moveit Mobile10/2/201617/6/2026
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.
ModificadaAlta (7.5)1.3%—Cisco 500 Series Switch Firmware30/1/201617/6/2026
The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.
ModificadaMedia (5.3)1.3%—Cisco 300 Series Managed Switch Firmware27/1/201617/6/2026
The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174.
ModificadaAlta (8.4)0.59%—HP Network Switch SoftwareHP J8692aHP J8693aHP J8697a+505/1/201617/6/2026
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859.
ModificadaAlta (7.8)0.48%—HP Network Switch Software5/1/201617/6/2026
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6860.
ModificadaMedia (6.5)2.0%—Jg786a HP Flexfabric 12500 4-port 100gbe CFP FDJg787a HP Flexfabric 12500 4-port 100gbe CFP FD TAAJg788a HP Flexfabric 12500 4-port 100gbe CFP FGJg789a HP Flexfabric 12500 4-port 100gbe CFP FG TAA+835/1/201617/6/2026
HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and forwarding (VRF) hopping."
ModificadaAlta (10)2.3%—Loytec L-switch AND L-ip Firmware21/12/201517/6/2026
LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backup file via unspecified vectors.
ModificadaAlta (7.1)1.4%—Lenovo Switch CenterIBM System Networking Switch Center12/11/201517/6/2026
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read…
ModificadaMedia (5)1.3%—Lenovo Switch CenterIBM System Networking Switch Center12/11/201517/6/2026
The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password.
ModificadaAlta (7.2)0.43%—IBM System Networking Switch CenterLenovo Switch Center12/11/201517/6/2026
The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows local users to execute arbitrary JSP code with SYSTEM privileges by using the Apache Axis AdminService deployment method to install a .jsp file.
ModificadaAlta (7.1)1.4%—IBM System Networking Switch CenterLenovo Switch Center12/11/201517/6/2026
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide FileReader.jsp input containing directory traversal sequences to read…