Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.8% | — | Xmlsoft Libxml2Xmlsoft LibxsltFedoraproject FedoraDebian Linux+15 | 3/5/2022 | 17/6/2026 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for… | |
| Modificada | Alta (7.5) | 0.70% | — | Cisco Adaptive Security ApplianceCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 21/4/2022 | 11/8/2026 | A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This… | |
| Analizada | Alta (7.5) | 1.2% | — | Cisco Umbrella Virtual Appliance | 21/4/2022 | 22/6/2026 | A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a man-in-the-middle… | |
| Modificada | Media (5.3) | 0.93% | — | Cisco WEB Security Appliance | 6/4/2022 | 17/6/2026 | A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device. This vulnerability is due to incorrect handling… | |
| Modificada | Media (6.5) | 0.88% | — | IBM MQ Appliance | 5/4/2022 | 17/6/2026 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487. | |
| Modificada | Media (5.3) | 1.1% | — | IBM MQ Appliance | 5/4/2022 | 17/6/2026 | IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance. | |
| Modificada | Alta (8.1) | 2.8% | — | TwistedDebian LinuxFedoraproject FedoraOracle ZFS Storage Appliance KIT | 4/4/2022 | 17/6/2026 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync… | |
| Modificada | Media (6.8) | 0.25% | — | Belden Tofino Xenon Security Appliance FirmwareBelden Tofino Argon Fa-tsa-220-tx/mm FirmwareBelden Tofino Argon Fa-tsa-220-tx/tx FirmwareBelden Tofino Argon Fa-tsa-220-mm/tx Firmware+9 | 3/4/2022 | 17/6/2026 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of… | |
| Modificada | Alta (7.5) | 0.88% | — | Belden Tofino Xenon Security Appliance FirmwareBelden Tofino Argon Fa-tsa-220-tx/mm FirmwareBelden Tofino Argon Fa-tsa-220-tx/tx FirmwareBelden Tofino Argon Fa-tsa-220-mm/tx Firmware+9 | 3/4/2022 | 17/6/2026 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401. | |
| Modificada | Crítica (9.8) | 0.90% | — | Belden Tofino Xenon Security Appliance FirmwareBelden Tofino Argon Fa-tsa-220-tx/mm FirmwareBelden Tofino Argon Fa-tsa-220-tx/tx FirmwareBelden Tofino Argon Fa-tsa-220-mm/tx Firmware+9 | 3/4/2022 | 17/6/2026 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state). | |
| Modificada | Alta (7.5) | 1.00% | — | Belden Tofino Xenon Security Appliance FirmwareBelden Tofino Argon Fa-tsa-220-tx/mm FirmwareBelden Tofino Argon Fa-tsa-220-tx/tx FirmwareBelden Tofino Argon Fa-tsa-220-mm/tx Firmware+7 | 3/4/2022 | 17/6/2026 | On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service. | |
| Modificada | Alta (7.5) | 0.88% | — | Belden Tofino Xenon Security Appliance FirmwareBelden Tofino Argon Fa-tsa-220-tx/mm FirmwareBelden Tofino Argon Fa-tsa-220-tx/tx FirmwareBelden Tofino Argon Fa-tsa-220-mm/tx Firmware+7 | 3/4/2022 | 17/6/2026 | On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer. | |
| Modificada | Media (6.8) | 0.41% | — | Belden Tofino Xenon Security Appliance FirmwareBelden Tofino Argon Fa-tsa-220-tx/mm FirmwareBelden Tofino Argon Fa-tsa-220-tx/tx FirmwareBelden Tofino Argon Fa-tsa-220-mm/tx Firmware+9 | 3/4/2022 | 17/6/2026 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, physically proximate attackers can execute code via a crafted file on a USB stick. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (6.5) | 0.98% | — | IBM MQ Appliance | 23/3/2022 | 17/6/2026 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to incorrectly configured authorization checks. IBM X-Force ID: 218276. | |
| Analizada | Crítica (9.8) | 50% | — | Apache Http ServerFedoraproject FedoraDebian LinuxOracle Http Server+1 | 14/3/2022 | 17/6/2026 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. | |
| Modificada | Crítica (9.1) | 42% | — | Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+4 | 14/3/2022 | 17/6/2026 | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. | |
| Modificada | Crítica (9.8) | 28% | 💥 PoC | Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+4 | 14/3/2022 | 17/6/2026 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | |
| Modificada | Alta (7.5) | 69% | — | Apache Http ServerDebian LinuxFedoraproject FedoraOracle Http Server+3 | 14/3/2022 | 17/6/2026 | A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | |
| Modificada | Alta (7.5) | 3.5% | — | TwistedDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+1 | 3/3/2022 | 17/6/2026 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc… | |
| Modificada | Media (6.1) | 21% | 💥 Exploit | Zyxel Zywall 2 Plus Internet Security Appliance Firmware | 1/3/2022 | 17/6/2026 | ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session… | |
| Modificada | Alta (7.5) | 5.1% | — | Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+31 | 26/2/2022 | 17/6/2026 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | |
| Modificada | Alta (7.5) | 3.1% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process. | |
| Modificada | Crítica (9.8) | 5.2% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution. | |
| Modificada | Crítica (9.8) | 2.7% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions. |