Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
484 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.85% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaScript in Shared Folders' names. | |
| Modificada | Alta (8.8) | 2.0% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions. | |
| Modificada | Media (6.5) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization. | |
| Modificada | Crítica (9.8) | 23% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. | |
| Modificada | Alta (8.8) | 5.9% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directory. | |
| Modificada | Media (4.8) | 0.86% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the edit password form. | |
| Modificada | Crítica (9.8) | 17% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the user's username. | |
| Modificada | Crítica (9.8) | 10% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation. | |
| Modificada | Crítica (9.8) | 9.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation. | |
| Modificada | Media (5.4) | 0.85% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing shared folders via their descriptions. | |
| Modificada | Media (6.1) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the permissions window by placing JavaScript in users' usernames. | |
| Modificada | Alta (7.5) | 2.3% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to arbitrary locations via the "path" URL parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing users by placing JavaScript in their usernames. | |
| Modificada | Alta (7.2) | 8.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the "groupname" parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript. | |
| Modificada | Media (6.1) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "options[sysname]" parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "lines" URL parameter. | |
| Modificada | Alta (7.8) | 0.36% | — | Broadcom Fabric Operating System | 8/11/2018 | 17/6/2026 | A Vulnerability in the supportsave command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access. | |
| Modificada | Alta (7.8) | 0.36% | — | Broadcom Fabric Operating System | 8/11/2018 | 17/6/2026 | A Vulnerability in the help command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access. | |
| Modificada | Alta (7.8) | 0.36% | — | Broadcom Fabric Operating System | 8/11/2018 | 17/6/2026 | A Vulnerability in the firmwaredownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access. | |
| Modificada | Alta (8.8) | 2.1% | — | Broadcom Fabric Operating System | 8/11/2018 | 17/6/2026 | A vulnerability in the Brocade Webtools firmware update section of Brocade Fabric OS before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote authenticated attackers to execute arbitrary commands. | |
| Modificada | Alta (7.8) | 0.39% | — | Broadcom Fabric Operating System | 8/11/2018 | 17/6/2026 | A vulnerability in Secure Shell implementation of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to provide arbitrary environment variables, and bypass the restricted configuration shell. | |
| Modificada | Alta (7.8) | 0.36% | — | Broadcom Fabric Operating System | 8/11/2018 | 17/6/2026 | A Vulnerability in the secryptocfg command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, and gain root access. |