Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
932 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Fabric Operating System | 21/2/2022 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system. | |
| Modificada | Media (6.5) | 0.91% | — | Broadcom Fabric Operating System | 21/2/2022 | 17/6/2026 | A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “factory” account, to read the contents of any file on the filesystem utilizing one of a few available binaries. | |
| Modificada | Media (6.1) | 0.72% | — | Broadcom Layer7 API Management Oauth Toolkit | 18/2/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attacks or other social engineering techniques. A successful attack allows injecting malicious code into… | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom Xcom Data Transport | 14/2/2022 | 17/6/2026 | XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges. | |
| Modificada | Media (5.5) | 0.71% | — | Broadcom Tcpreplay | 11/2/2022 | 17/6/2026 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. | |
| Modificada | Media (5.5) | 0.71% | — | Broadcom Tcpreplay | 11/2/2022 | 17/6/2026 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c | |
| Modificada | Alta (8.8) | 1.3% | — | Broadcom CA Harvest Software Change Manager | 4/2/2022 | 17/6/2026 | CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands. | |
| Modificada | Alta (8.2) | 0.33% | — | Insydeh2oSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+12 | 3/2/2022 | 11/8/2026 | An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to… | |
| Modificada | Alta (7.5) | 0.32% | — | Insydeh2oNetapp Fas/aff BiosSiemens Ruggedcom Ape1808 FirmwareSiemens Simatic Field PG M5 Firmware+14 | 3/2/2022 | 11/8/2026 | An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses. | |
| Modificada | Alta (7.5) | 0.28% | — | Insydeh2oSiemens Ruggedcom Ape1808 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+13 | 3/2/2022 | 11/8/2026 | A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring… | |
| Modificada | Media (6.1) | 0.72% | — | Broadcom Netmaster File Transfer ManagementBroadcom Netmaster Network Management FOR Tcp/ip | 18/1/2022 | 17/6/2026 | NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine. | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Media (6.5) | 0.90% | — | Broadcom CA Network Flow Analysis | 2/12/2021 | 17/6/2026 | CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensitive data. | |
| Modificada | Crítica (9.1) | 0.99% | — | Broadcom Emulex HBA Manager | 12/11/2021 | 17/6/2026 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a vulnerability in the remote firmware download feature that could allow a user to place or replace an arbitrary file on the remote host. In non-secure mode, the user is… | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom Emulex HBA Manager | 12/11/2021 | 17/6/2026 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform various attacks. In non-secure mode, the… | |
| Modificada | Alta (7.5) | 1.00% | — | Broadcom Emulex HBA Manager | 12/11/2021 | 17/6/2026 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, could allow a user to retrieve an arbitrary file from a remote host with the GetDumpFile command. In non-secure mode, the user is unauthenticated. | |
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Emulex HBA ManagerBroadcom ONE Command Manager | 3/11/2021 | 17/6/2026 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote GetDumpFile command that could allow a user to attempt various attacks. In non-secure mode, the user is unauthenticated | |
| Modificada | Alta (7.5) | 0.98% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+6 | 12/10/2021 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1), RUGGEDCOM ROX RX1511 (All versions <… | |
| Modificada | Alta (7.8) | 0.31% | — | Insydeh2oSiemens Ruggedcom Apr1808 FirmwareSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 Firmware+13 | 1/10/2021 | 11/8/2026 | A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.66% | — | Broadcom Tcpreplay | 22/9/2021 | 17/6/2026 | Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Alta (7.5) | 63% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+9 | 16/9/2021 | 17/6/2026 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). | |
| Modificada | Alta (7.5) | 65% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+14 | 16/9/2021 | 17/6/2026 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (5.3) | 0.75% | — | Siemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+6 | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1), RUGGEDCOM ROX RX1511 (All versions <… |