Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
ModificadaAlta (7.5)0.83%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
ModificadaAlta (7.5)0.59%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
ModificadaAlta (7.5)0.60%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
ModificadaMedia (5.5)0.12%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
ModificadaAlta (7.5)0.59%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
ModificadaAlta (7.5)0.35%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
ModificadaAlta (7.5)0.40%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
ModificadaCrítica (9.8)0.71%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
ModificadaMedia (6.5)0.58%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user
ModificadaCrítica (9.8)1.7%—Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware14/8/202317/6/2026
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
ModificadaCrítica (9.8)0.63%—Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware14/8/202317/6/2026
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
ModificadaCrítica (9.8)1.1%—Intel Ethernet Controller Rdma Driver FOR Linux11/8/202317/6/2026
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaMedia (4.7)0.11%—Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware11/8/202317/6/2026
Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.1)0.18%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+262/8/202317/6/2026
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate…
ModificadaMedia (5.4)0.34%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+152/8/202317/6/2026
A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (4.3)0.55%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+162/8/202317/6/2026
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.