Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 513 respecto a la semana anterior
Críticas / altas1299▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.3% | 💥 PoC | Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+2 | 18/4/2023 | 17/6/2026 | Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will… | |
| Modificada | Alta (7.2) | 0.96% | — | Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller | 14/4/2023 | 17/6/2026 | Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands. | |
| Modificada | Alta (8) | 0.25% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website. | |
| Modificada | Crítica (9.8) | 1.2% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions. | |
| Modificada | Crítica (9.8) | 0.77% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation… | |
| Modificada | Media (6.1) | 0.83% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site. | |
| Modificada | Crítica (9.8) | 0.89% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully… | |
| Modificada | Alta (7.5) | 1.5% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information. | |
| Modificada | Crítica (9.8) | 1.6% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script. | |
| Modificada | Crítica (9.8) | 18% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts. | |
| Modificada | Alta (7.5) | 0.65% | — | Propumpservice Osprey Pump Controller Firmware | 28/3/2023 | 17/6/2026 | Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product. | |
| Modificada | Media (6.7) | 0.24% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator… | |
| Modificada | Media (5.5) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this… | |
| Modificada | Alta (7.1) | 0.61% | 💥 PoC | Linux KernelNetapp HCI Baseboard Management Controller | 26/2/2023 | 17/6/2026 | In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. | |
| Modificada | Alta (8.8) | 0.36% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller | 23/2/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This… | |
| Modificada | Media (4.4) | 0.19% | — | Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+11 | 16/2/2023 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (4.9) | 0.51% | — | Intel Baseboard Management Controller Firmware | 16/2/2023 | 17/6/2026 | Uncaught exception in webserver for the Integrated BMC in some Intel(R) platforms before versions 2.86, 2.09 and 2.78 may allow a privileged user to potentially enable denial of service via network access. | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+9 | 1/2/2023 | 17/6/2026 | On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+9 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note:… | |
| Modificada | Media (6.1) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open… | |
| Modificada | Alta (8.5) | 73% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary. Note: Software versions… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Modificada | Media (4.9) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an… |