Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.56% | — | Oracle Hospitality Opera 5 Property Services | 17/10/2023 | 17/6/2026 | Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality OPERA 5 Property Services.… | |
| Modificada | Alta (8.8) | 0.67% | — | Oracle Hospitality Opera 5 Property Services | 17/10/2023 | 17/6/2026 | Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality OPERA 5 Property Services.… | |
| Modificada | Alta (8.8) | 0.58% | — | Kubernetes Operations | 12/10/2023 | 17/6/2026 | Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 4/10/2023 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modificada | Media (6.7) | 0.19% | — | Vmware Aria OperationsVmware Cloud Foundation | 27/9/2023 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Media (4.4) | 0.27% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command. | |
| Analizada | Media (4.4) | 0.17% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a through the passwdcfg command. This could allow an authenticated privileged user local user to crash a Brocade Fabric OS swith using the cli “passwdcfg --set -expire -minDiff“. | |
| Modificada | Alta (7.5) | 0.36% | — | Broadcom Fabric Operating System | 31/8/2023 | 17/6/2026 | The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS. | |
| Modificada | Crítica (9.8) | 67% | 💥 Exploit | Vmware Aria Operations FOR Networks | 29/8/2023 | 17/6/2026 | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI. | |
| Modificada | Alta (7.2) | 20% | — | Vmware Aria Operations FOR Networks | 29/8/2023 | 17/6/2026 | Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution. | |
| Modificada | Alta (7.5) | 0.89% | — | Nokia Service Router LinuxNokia Service Router Operating System | 29/8/2023 | 17/6/2026 | Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes. | |
| Modificada | Media (6) | 0.18% | — | Cisco Firepower Extensible Operating System | 23/8/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker… | |
| Modificada | Crítica (9.8) | 32% | 💥 Exploit | Terra-master Terramaster Operating System | 20/8/2023 | 17/6/2026 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials… | |
| Modificada | Media (5.3) | 0.64% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface. | |
| Modificada | Alta (7.1) | 0.16% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0. | |
| Modificada | Media (6.1) | 0.48% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application. | |
| Modificada | Alta (7.8) | 0.17% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0. | |
| Modificada | Media (5.5) | 0.28% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service. | |
| Modificada | Media (5.5) | 0.28% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service. | |
| Modificada | Media (5.5) | 0.18% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep. | |
| Modificada | Alta (7.8) | 0.21% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled. | |
| Modificada | Media (6.5) | 0.66% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive information. | |
| Modificada | Media (5.5) | 0.22% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands that can cause the content of shell interpreted… | |
| Modificada | Alta (7.8) | 0.27% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, “root” account access is disabled. |