Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
932 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host. | |
| Modificada | Media (5.4) | 0.51% | — | Broadcom Fabric Operating System | 25/9/2020 | 17/6/2026 | A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account. | |
| Modificada | Media (6.7) | 0.45% | — | Broadcom Rabbitmq ServerPivotal Software Rabbitmq | 31/8/2020 | 17/6/2026 | RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and… | |
| Modificada | Media (5.5) | 0.55% | — | Trustedcomputinggroup TrousersFedoraproject Fedora | 13/8/2020 | 17/6/2026 | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack. | |
| Analizada | Alta (7.4) | 13% | 💥 PoC | Openbsd OpensshNetapp A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+5 | 24/7/2020 | 17/6/2026 | scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking… | |
| Modificada | Crítica (9.8) | 1.4% | — | Broadcom Brocade Network Advisor | 29/6/2020 | 17/6/2026 | A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. | |
| Modificada | Alta (8.1) | 1.7% | — | Broadcom Spring Batch | 11/6/2020 | 1/9/2026 | When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". Spring Batch configures Jackson with global default typing enabled which means that through the… | |
| Modificada | Alta (7.5) | 15% | 💥 PoC | UI Unifi ControllerW1.fi HostapdAsus Rt-n11Broadcom Adsl+213 | 8/6/2020 | 17/6/2026 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. | |
| Modificada | Media (6) | 2.9% | 💥 PoC | Docker EngineFedoraproject FedoraDebian LinuxBroadcom Sannav | 2/6/2020 | 17/6/2026 | An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service. | |
| Modificada | Media (6.5) | 2.0% | — | Gnome BalsaGnome Glib-networkingCanonical Ubuntu LinuxFedoraproject Fedora+2 | 28/5/2020 | 17/6/2026 | In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications… | |
| Modificada | Crítica (9.1) | 1.7% | — | Broadcom TcpreplayFedoraproject Fedora | 8/5/2020 | 17/6/2026 | tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c. | |
| Modificada | Alta (7.5) | 4.4% | — | OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+14 | 28/4/2020 | 17/6/2026 | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). | |
| Modificada | Alta (7.5) | 53% | 💥 PoC | OpensslDebian LinuxFreebsdFedoraproject Fedora+22 | 21/4/2020 | 17/6/2026 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from… | |
| Modificada | Media (6.5) | 1.4% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information. | |
| Modificada | Media (4.3) | 0.92% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action. | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization. | |
| Modificada | Alta (8.8) | 3.0% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges. | |
| Modificada | Media (6.1) | 1.6% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks. | |
| Modificada | Media (6.1) | 1.4% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks. | |
| Modificada | Media (6.1) | 1.3% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks. | |
| Modificada | Alta (7.5) | 3.2% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information. | |
| Modificada | Alta (8.1) | 1.9% | — | Broadcom CA API Developer Portal | 15/4/2020 | 17/6/2026 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data. | |
| Modificada | Media (6.5) | 1.3% | — | Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg | 10/4/2020 | 17/6/2026 | The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console. | |
| Modificada | Media (6.1) | 57% | — | Apache Http ServerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+10 | 2/4/2020 | 17/6/2026 | In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL. | |
| Modificada | Alta (7.5) | 1.1% | — | Broadcom Reactor Netty | 3/3/2020 | 4/9/2026 | Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response. |