Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.29% | — | F5 Big-ip Access Policy Manager | 3/5/2023 | 17/6/2026 | An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.9) | 0.22% | — | F5 Big-ip Access Policy Manager | 3/5/2023 | 17/6/2026 | In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.5) | 0.74% | — | F5 NJS | 9/4/2023 | 17/6/2026 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. | |
| Modificada | Alta (7.5) | 0.66% | — | F5 NJS | 9/4/2023 | 17/6/2026 | Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. | |
| Modificada | Alta (7.5) | 0.74% | — | F5 NJS | 9/4/2023 | 17/6/2026 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. | |
| Modificada | Alta (7.5) | 0.73% | — | F5 NJS | 9/4/2023 | 17/6/2026 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. | |
| Analizada | Crítica (9.8) | 1.3% | — | F5 NJS | 4/4/2023 | 17/6/2026 | Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function. | |
| Analizada | Crítica (9.8) | 1.3% | — | F5 NJS | 4/4/2023 | 17/6/2026 | Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file. | |
| Modificada | Media (5.5) | 0.22% | — | F5 Nginx AgentF5 Nginx Instance Manager | 29/3/2023 | 17/6/2026 | Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace… | |
| Modificada | Alta (8.8) | 1.1% | — | Canon D1620 FirmwareCanon D1650 FirmwareCanon D1520 FirmwareCanon D1550 Firmware+72 | 28/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the privet API. The issue results from the lack of proper validation of the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Canon D1620 FirmwareCanon D1650 FirmwareCanon D1520 FirmwareCanon D1550 Firmware+72 | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SLP protocol. The issue results from the lack of proper… | |
| Modificada | Alta (8.8) | 1.2% | — | Canon D1620 FirmwareCanon D1650 FirmwareCanon D1520 FirmwareCanon D1550 Firmware+72 | 28/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CADM service. The issue results from the lack of proper validation of… | |
| Modificada | Media (4.7) | 0.28% | — | AMD Athlon X4 750 FirmwareAMD Athlon X4 760k FirmwareAMD Athlon X4 830 FirmwareAMD Athlon X4 840 Firmware+161 | 1/3/2023 | 17/6/2026 | When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure. | |
| Modificada | Media (5.3) | 0.44% | — | Dahuasecurity Ipc-hf71242f-z-x FirmwareDahuasecurity Ipc-hf7442f-z-x FirmwareDahuasecurity Ipc-hf7842f-z-x FirmwareDahuasecurity Ipc-hf5241f-ze Firmware+93 | 9/2/2023 | 17/6/2026 | Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time. | |
| Modificada | Media (6.5) | 0.30% | — | Microchip Dt100112 FirmwareNordicsemi Nrf5340-dk Firmware | 8/2/2023 | 17/6/2026 | Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet. | |
| Modificada | Alta (7.5) | 1.5% | — | Hdfgroup Hdf5 | 3/2/2023 | 17/6/2026 | Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c. | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+9 | 1/2/2023 | 17/6/2026 | On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.… | |
| Modificada | Alta (7.5) | 1.5% | — | F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security Manager | 1/2/2023 | 17/6/2026 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Domain Name SystemF5 Big-ip Local Traffic ManagerF5 Big-ip 10000s FirmwareF5 Big-ip 10200v Firmware+30 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+9 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which… | |
| Modificada | Alta (7.8) | 0.44% | — | F5os-aF5os-c | 1/2/2023 | 17/6/2026 | On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note:… | |
| Modificada | Media (6.1) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open… | |
| Modificada | Alta (8.5) | 73% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary. Note: Software versions… |