Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
ModificadaAlta (7.5)0.83%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
ModificadaAlta (7.5)0.59%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
ModificadaAlta (7.5)0.60%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
ModificadaMedia (5.5)0.12%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
ModificadaAlta (7.5)0.59%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
ModificadaAlta (7.5)0.35%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
ModificadaAlta (7.5)0.40%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
ModificadaCrítica (9.8)0.71%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
ModificadaMedia (6.5)0.58%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user
ModificadaCrítica (9.8)1.7%—Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware14/8/202317/6/2026
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
ModificadaCrítica (9.8)0.63%—Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware14/8/202317/6/2026
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
ModificadaCrítica (9.8)1.1%—Intel Ethernet Controller Rdma Driver FOR Linux11/8/202317/6/2026
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaMedia (4.7)0.11%—Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware11/8/202317/6/2026
Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.4)1.2%—Apache Roller6/8/202317/6/2026
Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted users, then you need to do nothing because…