Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

484 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.40%—Cisco Firepower Extensible Operating SystemCisco Unified Computing System7/4/201717/6/2026
A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More…
ModificadaAlta (7.8)0.81%—Cisco Unified Computing SystemCisco Firepower Extensible Operating System7/4/201717/6/2026
A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394…
ModificadaMedia (5.9)2.1%—A10networks Advanced Core Operating System8/2/201717/6/2026
A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.
ModificadaCrítica (9.8)4.4%💥 PoCAvaya VSP Operating System Software23/1/201717/6/2026
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.
ModificadaMedia (6.5)2.1%—Broadcom Fabric Operating System22/8/201617/6/2026
HPE FOS before 7.4.1d and 8.x before 8.0.1 on StoreFabric B switches allows remote attackers to obtain sensitive information via unspecified vectors.
ModificadaCrítica (9.8)8.7%—Cisco Firepower Extensible Operating SystemCisco Unified Computing System22/1/201617/6/2026
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.
ModificadaBaja (3.7)1.7%—Toshiba 4690 Operating System31/12/201517/6/2026
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
ModificadaMedia (6.5)1.1%—Cisco Firepower Extensible Operating System24/11/201517/6/2026
An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622.
ModificadaMedia (4.3)0.82%—Cisco Firepower Extensible Operating System19/11/201517/6/2026
The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604.
ModificadaMedia (4)0.97%—Cisco Firepower Extensible Operating System19/11/201517/6/2026
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.
ModificadaAlta (7.2)0.39%—Cisco Firepower Extensible Operating System19/11/201517/6/2026
The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.
ModificadaMedia (4.9)0.31%—Cisco Firepower Extensible Operating System19/11/201517/6/2026
The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531.
ModificadaMedia (5)1.2%—Cisco Firepower Extensible Operating System19/11/201517/6/2026
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.
ModificadaMedia (6.8)0.59%—Cisco Firepower Extensible Operating System18/11/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux10611.
ModificadaMedia (4.3)0.96%—Cisco Firepower Extensible Operating System18/11/201517/6/2026
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux10614.
ModificadaBaja (3.3)0.93%—Siemens Ruggedcom Rugged Operating System28/10/201517/6/2026
Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.
ModificadaMedia (4.3)0.81%—Siemens Ruggedcom Rugged Operating System11/9/201517/6/2026
Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.
ModificadaMedia (6.8)1.6%—Cisco Edge Bluebird Operating System19/8/201517/6/2026
The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuu43968.
ModificadaMedia (4.3)1.1%—Siemens Ruggedcom ROX II FirmwareSiemens Ruggedcom Rugged Operating System3/8/201517/6/2026
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.
ModificadaMedia (5)1.3%—Cisco Firepower Extensible Operating System29/7/201517/6/2026
Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and obtain sensitive device information by visiting an unspecified web page, aka Bug ID CSCuu82230.
ModificadaMedia (5)12%💥 ExploitA10networks Advanced Core Operating System5/6/201417/6/2026
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third…
ModificadaBaja (3)0.28%—Toshibacommerce 4690 Point OF Sale Operating System21/4/201417/6/2026
The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hashes passwords with the ADXCRYPT algorithm, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified cryptanalysis of an ADXCSOUF.DAT file.
ModificadaMedia (5)2.4%—Siemens Ruggedcom Rugged Operating System1/4/201417/6/2026
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
ModificadaAlta (7.8)2.2%—Siemens Ruggedcom Rugged Operating System24/2/201417/6/2026
The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (device outage) via crafted packets.
ModificadaAlta (8)1.5%—Siemens Ruggedcom Rugged Operating System17/12/201317/6/2026
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.
Orbitaley — Vulnerabilidades