Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

61 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.12%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
ModificadaAlta (7.5)0.59%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
ModificadaAlta (7.5)0.35%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
ModificadaAlta (7.5)0.40%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
ModificadaCrítica (9.8)0.71%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
ModificadaMedia (6.5)0.58%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user
ModificadaAlta (8.8)0.97%—Pi-hole WEB Interface26/1/202317/6/2026
Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes it possible for an attacker to "pass the…
ModificadaMedia (6.1)0.42%—Eyesofnetwork WEB Interface8/11/202217/6/2026
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php.
ModificadaMedia (4.8)0.40%—Eyesofnetwork WEB Interface8/11/202217/6/2026
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php.
ModificadaMedia (4.8)0.40%—Eyesofnetwork WEB Interface8/11/202217/6/2026
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php.
ModificadaMedia (5.4)0.90%—Pi-hole WEB Interface26/10/202117/6/2026
Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was patched in version 5.8.
ModificadaMedia (6.1)0.55%—Pi-hole WEB Interface17/9/202117/6/2026
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.1)0.55%—Pi-hole WEB Interface17/9/202117/6/2026
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.5)1.1%—Pi-hole WEB Interface15/9/202117/6/2026
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
ModificadaAlta (8.8)0.67%—Pi-hole FtldnsPi-holePi-hole WEB Interface15/4/202117/6/2026
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
ModificadaMedia (6.5)2.6%—Tesla Model 3 WEB Interface20/3/202017/6/2026
The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other…
ModificadaAlta (7.5)1.8%—Dell Avamar Data Migration Enabler WEB Interface19/6/201917/6/2026
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent2/3/201817/6/2026
SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (9.7)3.8%—Broadcom Pipa C211 WEB InterfaceBroadcom Pipa C21114/5/201417/6/2026
cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors.
ModificadaMedia (4.3)7.2%—Solarwinds IP Address Manager WEB InterfaceSolarwinds Orion Network Performance Monitor31/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.