Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
932 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (4.3) | 0.88% | — | Broadcom Fabric Operating System | 11/12/2020 | 17/6/2026 | Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges if it is not associated with any groups. | |
| Modificada | Media (6.7) | 0.31% | — | Broadcom Fabric Operating System | 11/12/2020 | 17/6/2026 | Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated user to run arbitrary commands and perform escalation of privileges. | |
| Modificada | Media (4.9) | 0.87% | — | Broadcom Symantec Messaging Gateway | 10/12/2020 | 17/6/2026 | An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4. | |
| Modificada | Alta (7.2) | 1.5% | — | Broadcom Symantec Messaging Gateway | 10/12/2020 | 17/6/2026 | A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 10.7.4. | |
| Modificada | Alta (7.8) | 1.1% | 💥 PoC | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+8 | 9/12/2020 | 17/6/2026 | A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. | |
| Modificada | Media (4.4) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 9/12/2020 | 17/6/2026 | A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24. | |
| Modificada | Media (6.7) | 0.93% | 💥 PoC | Linux KernelBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+15 | 23/11/2020 | 17/6/2026 | Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field. | |
| Modificada | Alta (7.8) | 0.30% | — | Broadcom Unified Infrastructure Management | 23/11/2020 | 17/6/2026 | CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that allows local attackers to elevate privileges. | |
| Modificada | Media (6) | 0.30% | — | Trustedcomputinggroup Trusted Platform Module | 18/11/2020 | 17/6/2026 | Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack. | |
| Modificada | Alta (7.5) | 1.4% | — | Mozilla Network Security ServicesSiemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+5 | 22/10/2020 | 17/6/2026 | In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. | |
| Modificada | Crítica (9.8) | 3.6% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+9 | 22/10/2020 | 17/6/2026 | In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow. | |
| Modificada | Media (6.5) | 2.0% | — | Mozilla Network Security ServicesSiemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+5 | 22/10/2020 | 17/6/2026 | In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service. | |
| Modificada | Media (5.9) | 0.93% | — | Broadcom Vmware Nsx-t Data CenterVmware Cloud Foundation | 20/10/2020 | 17/6/2026 | VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node. | |
| Modificada | Alta (7.5) | 2.6% | — | Broadcom TcpreplayFedoraproject Fedora | 19/10/2020 | 17/6/2026 | An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service. | |
| Modificada | Alta (7.5) | 2.6% | — | Broadcom TcpreplayFedoraproject Fedora | 19/10/2020 | 17/6/2026 | An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service. | |
| Modificada | Crítica (9.8) | 1.2% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input. | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated attackers to perform various attacks. | |
| Modificada | Media (5.5) | 0.34% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging. | |
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability. | |
| Modificada | Media (6.5) | 1.0% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files. | |
| Modificada | Alta (8.8) | 1.0% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host. | |
| Modificada | Alta (8.8) | 1.9% | — | Broadcom Brocade Sannav | 25/9/2020 | 17/6/2026 | A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process. | |
| Modificada | Crítica (9.8) | 1.0% | — | Broadcom Brocade Sannav | 25/9/2020 | 17/6/2026 | Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability. | |
| Modificada | Media (6.1) | 0.77% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers |