Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 2.4% | — | Cisco Nx-osCisco Firepower Extensible Operating SystemCisco Fx-os | 16/5/2019 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly. The vulnerability is… | |
| Modificada | Media (6.7) | 0.48% | — | Cisco Nx-osCisco Firepower Extensible Operating System | 15/5/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Firepower Extensible Operating SystemCisco Nx-os | 15/5/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI… | |
| Modificada | Media (4.4) | 0.38% | — | Cisco Firepower Extensible Operating SystemCisco Nx-os | 7/3/2019 | 17/6/2026 | A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco Firepower Extensible Operating SystemCisco Nx-os | 7/3/2019 | 17/6/2026 | Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco Firepower Extensible Operating SystemCisco Nx-os | 7/3/2019 | 17/6/2026 | Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due… | |
| Modificada | Crítica (9.1) | 2.2% | — | Broadcom Fabric Operating System | 3/12/2018 | 17/6/2026 | A vulnerability in the proxy service of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote unauthenticated attackers to obtain sensitive information and possibly cause a denial of service attack. | |
| Modificada | Alta (7.8) | 0.35% | — | Broadcom Fabric Operating System | 3/12/2018 | 17/6/2026 | A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access. | |
| Modificada | Alta (8.8) | 5.2% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter. | |
| Modificada | Media (5.3) | 17% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter. | |
| Modificada | Alta (8.8) | 20% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter. | |
| Modificada | Alta (8.8) | 25% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter. | |
| Modificada | Media (5.4) | 0.85% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaScript in Shared Folders' names. | |
| Modificada | Alta (8.8) | 2.0% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions. | |
| Modificada | Media (6.5) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization. | |
| Modificada | Crítica (9.8) | 23% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. | |
| Modificada | Alta (8.8) | 5.9% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directory. | |
| Modificada | Media (4.8) | 0.86% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the edit password form. | |
| Modificada | Crítica (9.8) | 17% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the user's username. | |
| Modificada | Crítica (9.8) | 10% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation. | |
| Modificada | Crítica (9.8) | 9.1% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation. | |
| Modificada | Media (5.4) | 0.85% | — | Terra-master Terramaster Operating System | 27/11/2018 | 17/6/2026 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing shared folders via their descriptions. |