Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

445 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.4%—IBM Qlogic 4 GB Fibre Channel Expansion Card FirmwareIBM Qlogic 20-port 4/8 GB SAN Switch Module Firmware10/10/201817/6/2026
The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password.
ModificadaAlta (7.5)2.0%—Datachannel-client Project Datachannel-client7/6/201817/6/2026
datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaCrítica (9.8)11%💥 ExploitConarc Ichannel19/12/201717/6/2026
Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service).
ModificadaAlta (7.5)3.6%—Viprinet Multichannel VPN Router 300 Firmware20/1/201717/6/2026
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows remote attackers to perform a replay attack.
ModificadaMedia (5.9)1.7%—Viprinet Multichannel VPN Router 300 Firmware20/1/201717/6/2026
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.
ModificadaMedia (6.1)4.5%💥 ExploitViprinet Multichannel VPN Router 300 Firmware20/1/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the username when (1) logging in or (2) creating an account in the old interface, (3) username when creating an account in the new…
ModificadaMedia (6.8)1.1%💥 ExploitChialab & Channelweb Bedita3/1/201516/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) modify credentials via a data array to admin/saveUser.
ModificadaMedia (4.3)0.97%—Chialab & Channelweb Bedita3/1/201516/6/2026
Cross-site scripting (XSS) vulnerability in controllers/home_controller.php in BEdita before 3.1 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter to news/index.
ModificadaMedia (6.5)1.7%—Jexperts Channel Platform25/11/201417/6/2026
JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action and key parameters.
ModificadaMedia (4.3)1.9%—Jexperts Channel Platform13/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in JExperts Channel Platform 5.0.33_CCB allow remote attackers to inject arbitrary web script or HTML via the (1) usuario.nome variable in an editarUsuario action to usuario.do or (2) titulo.form variable in a novoChamado action to ticket.do.
ModificadaMedia (5.4)0.27%—Weather Channel24/9/201417/6/2026
The Weather Channel (aka com.weather.Weather) application 5.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Wsaudichannelalnas Project Wsaudichannelalnas23/9/201417/6/2026
The wSaudichannelAlNasr (aka com.wSaudichannelAlNasr) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaBaja (1.7)1.2%—HP H-series Fibre Channel Switch FirmwareHP 8/20q Fibre Channel Switch 16 PortHP 8/20q Fibre Channel Switch 8 PortHP 8GB Simple SAN Connection KIT+310/5/201417/6/2026
Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before 8.0.14.08.00 allows remote authenticated users to obtain sensitive information via unknown vectors.
ModificadaBaja (3.5)1.4%—IBM Sterling Multi-channel Fulfillment SolutionIBM Sterling Selling AND Fulfillment Foundation10/5/201316/6/2026
The Sterling Order Management APIs in IBM Sterling Multi-Channel Fulfillment Solution 8.0 before HF128 and IBM Sterling Selling and Fulfillment Foundation 8.5 before HF93, 9.0 before HF73, 9.1.0 before FP45, and 9.2.0 before FP17, when the API tester is enabled, do not require administrative credentials, which allows…
ModificadaMedia (4.3)1.1%—IBM Sterling Multi-channel Fulfillment SolutionIBM Sterling Selling AND Fulfillment Foundation19/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.5)1.1%—IBM Sterling Multi-channel Fulfillment SolutionIBM Sterling Selling AND Fulfillment Foundation19/3/201316/6/2026
IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.
ModificadaAlta (7.8)4.9%—HP Storageworks P2000 G3 MSA Fc/iscsi Dual Combo Controller LFF Array SystemHP Storageworks P2000 G3 MSA Fibre Channel Dual Controller LFF Array SystemHP Storageworks P2000 G3 MSA Fibre Channel Dual Controller SFF Array System13/1/201216/6/2026
Absolute path traversal vulnerability in the web interface on HP StorageWorks P2000 G3 MSA array systems allows remote attackers to read arbitrary files via a pathname in the URI.
ModificadaMedia (4.3)1.5%💥 ExploitFirmchannel Digital Signage5/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.
ModificadaAlta (9.3)6.7%—Photochannel PNI Digital Media Upload Plugin Activex Control18/9/200716/6/2026
Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5)4.2%—Brocade SilkwormBrocade Silkworm Fiber Channel SwitchEngenio Storage ControllerIBM Ds4100+24/9/200416/6/2026
Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.
Orbitaley — Vulnerabilidades