Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.0%—Linux KernelNetapp Active IQ Unified ManagerNetapp AFF Baseboard Management ControllerNetapp Cloud Backup+1118/11/201917/6/2026
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762.
ModificadaMedia (5.5)0.21%—Broadcom Brocade Sannav8/11/201917/6/2026
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
ModificadaAlta (7.4)0.74%—Broadcom Brocade Sannav8/11/201917/6/2026
A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections.
ModificadaAlta (7.5)0.40%—Broadcom Brocade Sannav8/11/201917/6/2026
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).
ModificadaAlta (7.8)0.25%—Broadcom Brocade Sannav8/11/201917/6/2026
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.
ModificadaMedia (5.5)0.20%—Broadcom Brocade Sannav8/11/201917/6/2026
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.
ModificadaAlta (8.8)1.3%—Broadcom Brocade Sannav8/11/201917/6/2026
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal.
ModificadaCrítica (9.8)3.4%—Linux KernelOpensuse LeapRedhat Enterprise LinuxNetapp Active IQ Unified Manager+137/11/201917/6/2026
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other…
ModificadaAlta (7)0.99%💥 PoCLinux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+144/11/201917/6/2026
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this…
ModificadaAlta (8.8)2.5%—Broadcom CA Performance ManagementBroadcom Network Operations17/10/201917/6/2026
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.
ModificadaAlta (8.6)0.89%—Broadcom Reactor Netty17/10/20194/9/2026
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
ModificadaCrítica (9.8)3.4%—Broadcom Network Flow Analysis2/10/201917/6/2026
CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.
ModificadaCrítica (9.8)5.8%—Broadcom CA Client AutomationBroadcom CA Workload Automation AE6/9/201917/6/2026
An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.
ModificadaMedia (6.5)0.59%—Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg30/8/201917/6/2026
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain plaintext authentication credentials for a remote FTP server from the…
ModificadaMedia (6.1)0.77%—Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg30/8/201917/6/2026
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject malicious JavaScript code in ASG/ProxySG's web listing of a remote FTP…
ModificadaAlta (8.8)1.0%—Broadcom Bcm4335c0 FirmwareBroadcom Bcm43438a1 FirmwareCypress Cyw20702a1kwfbg FirmwareCypress Cyw20702a1kwfbgt Firmware+597/6/201917/6/2026
Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.
ModificadaCrítica (9.1)1.7%—Broadcom Privileged Access Manager26/2/201917/6/2026
An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.
ModificadaAlta (7.8)1.1%—Broadcom TcpreplayFedoraproject Fedora17/2/201917/6/2026
An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
ModificadaAlta (7.8)1.3%—Broadcom TcpreplayFedoraproject Fedora17/2/201917/6/2026
An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified…
ModificadaAlta (7.8)1.3%—Broadcom TcpreplayFedoraproject Fedora17/2/201917/6/2026
An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other…
ModificadaMedia (6.1)2.0%—Broadcom Automic Workload Automation6/2/201917/6/2026
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.
ModificadaCrítica (9.8)1.2%—Broadcom Service Desk ManagerCA Service Desk Manager22/1/201917/6/2026
CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.
ModificadaAlta (7.5)1.3%—Broadcom Service Desk ManagerCA Service Desk Manager22/1/201917/6/2026
CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.
ModificadaCrítica (9.8)3.0%—Broadcom Spring Batch18/1/20191/9/2026
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
ModificadaCrítica (9.8)4.1%—Broadcom Spring WEB ServicesOracle Financial Services Analytical Applications InfrastructureOracle Flexcube Private Banking18/1/20194/9/2026
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Orbitaley — Vulnerabilidades