Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.12% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server | |
| Modificada | Alta (7.5) | 0.59% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file | |
| Modificada | Alta (7.5) | 0.35% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux | |
| Modificada | Alta (7.5) | 0.40% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers | |
| Modificada | Crítica (9.8) | 0.71% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup | |
| Modificada | Media (6.5) | 0.58% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user | |
| Modificada | Alta (8.8) | 0.97% | — | Pi-hole WEB Interface | 26/1/2023 | 17/6/2026 | Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes it possible for an attacker to "pass the… | |
| Modificada | Media (6.1) | 0.42% | — | Eyesofnetwork WEB Interface | 8/11/2022 | 17/6/2026 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php. | |
| Modificada | Media (4.8) | 0.40% | — | Eyesofnetwork WEB Interface | 8/11/2022 | 17/6/2026 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php. | |
| Modificada | Media (4.8) | 0.40% | — | Eyesofnetwork WEB Interface | 8/11/2022 | 17/6/2026 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php. | |
| Modificada | Media (5.4) | 0.90% | — | Pi-hole WEB Interface | 26/10/2021 | 17/6/2026 | Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was patched in version 5.8. | |
| Modificada | Media (6.1) | 0.55% | — | Pi-hole WEB Interface | 17/9/2021 | 17/6/2026 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 0.55% | — | Pi-hole WEB Interface | 17/9/2021 | 17/6/2026 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.5) | 1.1% | — | Pi-hole WEB Interface | 15/9/2021 | 17/6/2026 | adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag | |
| Modificada | Alta (8.8) | 0.67% | — | Pi-hole FtldnsPi-holePi-hole WEB Interface | 15/4/2021 | 17/6/2026 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details. | |
| Modificada | Media (6.5) | 2.6% | — | Tesla Model 3 WEB Interface | 20/3/2020 | 17/6/2026 | The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other… | |
| Modificada | Alta (7.5) | 1.8% | — | Dell Avamar Data Migration Enabler WEB Interface | 19/6/2019 | 17/6/2026 | Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (9.7) | 3.8% | — | Broadcom Pipa C211 WEB InterfaceBroadcom Pipa C211 | 14/5/2014 | 17/6/2026 | cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors. | |
| Modificada | Media (4.3) | 7.2% | — | Solarwinds IP Address Manager WEB InterfaceSolarwinds Orion Network Performance Monitor | 31/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field. |