Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.3%—Kemptechnologies Loadmaster Operating System25/5/201817/6/2026
A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (LTS) LMOS before 7.1.35.5 related to Session Management could allow an unauthenticated, remote attacker to bypass security protections, gain system privileges, and execute elevated commands such as…
ModificadaMedia (6.5)0.54%—Broadcom Fabric Operating SystemBrocade Fabric OS8/2/201817/6/2026
A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow an attacker to cause a denial of service (CPU consumption and device hang) condition by sending crafted Router Advertisement (RA) messages to a targeted system.
ModificadaMedia (6.1)1.4%—Broadcom Fabric Operating SystemBrocade Fabric OS8/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to execute arbitrary code or access sensitive browser-based information.
ModificadaAlta (7)0.27%—Lenovo Enterprise Network Operating System10/1/201817/6/2026
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces. This bypass mechanism can be accessed when performing local…
ModificadaMedia (6.1)1.3%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
ModificadaMedia (6.1)1.3%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
ModificadaMedia (6.1)1.4%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
ModificadaMedia (6.1)1.3%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
ModificadaMedia (6.3)1.1%—Cisco Nx-osCisco Unified Computing SystemCisco Firepower Extensible Operating System30/11/201717/6/2026
A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this…
ModificadaMedia (5.3)1.2%—Cisco Firepower Extensible Operating System16/11/201717/6/2026
A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, bypassing any filters that are configured to deny local IP…
ModificadaAlta (8.8)3.8%—Cisco Firepower Extensible Operating System2/11/201717/6/2026
A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges. The vulnerability is due to…
ModificadaAlta (8.6)4.5%—Cisco Firepower Extensible Operating SystemCisco FxosCisco Nx-os19/10/201717/6/2026
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the…
ModificadaCrítica (9.8)7.4%—Terra-master Terramaster Operating System15/9/201717/6/2026
Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.
ModificadaAlta (8.8)3.1%—Broadcom Fabric Operating System8/5/201717/6/2026
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected versions, non-root users…
ModificadaMedia (4.4)0.80%—Cisco Firepower Extensible Operating SystemCisco Unified Computing System7/4/201717/6/2026
A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb66189 CSCvb86775. Known…
ModificadaAlta (7.1)0.82%—Cisco Firepower Extensible Operating SystemCisco Unified Computing System7/4/201717/6/2026
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known…
ModificadaAlta (7.8)0.81%—Cisco Firepower Extensible Operating SystemCisco Unified Computing System7/4/201717/6/2026
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61351 CSCvb61637. Known…
ModificadaMedia (6.7)0.40%—Cisco Firepower Extensible Operating SystemCisco Unified Computing System7/4/201717/6/2026
A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More…
ModificadaAlta (7.8)0.81%—Cisco Unified Computing SystemCisco Firepower Extensible Operating System7/4/201717/6/2026
A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394…
ModificadaMedia (5.9)2.1%—A10networks Advanced Core Operating System8/2/201717/6/2026
A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.
ModificadaCrítica (9.8)4.4%💥 PoCAvaya VSP Operating System Software23/1/201717/6/2026
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.
Orbitaley — Vulnerabilidades