Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.1%—Terra-master Terramaster Operating System27/11/201817/6/2026
Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the permissions window by placing JavaScript in users' usernames.
ModificadaAlta (7.5)2.3%—Terra-master Terramaster Operating System27/11/201817/6/2026
Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to arbitrary locations via the "path" URL parameter.
ModificadaMedia (6.1)1.1%—Terra-master Terramaster Operating System27/11/201817/6/2026
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing users by placing JavaScript in their usernames.
ModificadaAlta (7.2)8.1%—Terra-master Terramaster Operating System27/11/201817/6/2026
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the "groupname" parameter.
ModificadaMedia (5.4)1.2%—Terra-master Terramaster Operating System27/11/201817/6/2026
Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript.
ModificadaMedia (6.1)1.1%—Terra-master Terramaster Operating System27/11/201817/6/2026
Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "options[sysname]" parameter.
ModificadaMedia (6.1)1.1%—Terra-master Terramaster Operating System27/11/201817/6/2026
Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "lines" URL parameter.
ModificadaAlta (7.8)0.36%—Broadcom Fabric Operating System8/11/201817/6/2026
A Vulnerability in the supportsave command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
ModificadaAlta (7.8)0.36%—Broadcom Fabric Operating System8/11/201817/6/2026
A Vulnerability in the help command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
ModificadaAlta (7.8)0.36%—Broadcom Fabric Operating System8/11/201817/6/2026
A Vulnerability in the firmwaredownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.
ModificadaAlta (8.8)2.1%—Broadcom Fabric Operating System8/11/201817/6/2026
A vulnerability in the Brocade Webtools firmware update section of Brocade Fabric OS before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote authenticated attackers to execute arbitrary commands.
ModificadaAlta (7.8)0.39%—Broadcom Fabric Operating System8/11/201817/6/2026
A vulnerability in Secure Shell implementation of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to provide arbitrary environment variables, and bypass the restricted configuration shell.
ModificadaAlta (7.8)0.36%—Broadcom Fabric Operating System8/11/201817/6/2026
A Vulnerability in the secryptocfg command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, and gain root access.
ModificadaAlta (7.5)1.2%—Broadcom Fabric Operating System8/11/201817/6/2026
A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow attackers to intercept or manipulate a user's session ID.
ModificadaMedia (5.5)0.34%—Broadcom Fabric Operating System8/11/201817/6/2026
A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to bypass the export file access restrictions and initiate a file copy from the source to a remote system.
ModificadaMedia (5.3)0.79%—Cisco Nx-osCisco Firepower Extensible Operating System17/10/201817/6/2026
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of…
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaMedia (5.3)0.74%—IBM Network Operating System13/7/201816/6/2026
The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames with unknown MAC addresses out on all interfaces on the same VLAN, which might allow remote attackers…
ModificadaMedia (6.5)0.64%—Cisco Nx-osCisco Firepower Extensible Operating SystemCisco Fxos21/6/201817/6/2026
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly…
ModificadaAlta (7.5)2.8%—Cisco Nx-osCisco Firepower Extensible Operating System21/6/201817/6/2026
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric…
ModificadaCrítica (9.8)4.1%—Cisco Nx-osCisco Firepower Extensible Operating System21/6/201817/6/2026
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive information from memory or cause a denial of service (DoS) condition on the affected product. The vulnerability exists because the affected software…
ModificadaAlta (8.8)1.1%—Cisco Nx-osCisco Firepower Extensible Operating System21/6/201817/6/2026
A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on the affected device. The vulnerability exists because of insufficiently validated…
ModificadaAlta (7.8)0.43%—Cisco Nx-osCisco Firepower Extensible Operating System21/6/201817/6/2026
A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem. An attacker could exploit this…
ModificadaAlta (7.5)2.0%—Cisco Nx-osCisco Firepower Extensible Operating System21/6/201817/6/2026
A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to incorrect input validation in the web UI. An attacker could exploit this vulnerability by sending a…
ModificadaMedia (6.7)0.45%—Cisco Nx-osCisco Firepower Extensible Operating SystemCisco Fxos20/6/201817/6/2026
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not properly delete sensitive files when certain…
Orbitaley — Vulnerabilidades