Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.16% | — | Broadcom Sannav | 2/2/2026 | 17/6/2026 | A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and… | |
| Analizada | Baja (2.3) | 0.30% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Alta (7.1) | 0.14% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier. | |
| Analizada | Baja (2.3) | 0.27% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Alta (8.7) | 0.35% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Media (5.3) | 0.17% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier. | |
| Analizada | Baja (2.3) | 0.24% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Baja (2.3) | 0.32% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (7.1) | 0.90% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier. | |
| Analizada | Media (5.3) | 0.16% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Reflected XSS.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (8.8) | 0.33% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Aplazada | Alta (7.3) | 0.14% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.16% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Analizada | Alta (7.5) | 0.39% | — | Broadcom Tcpreplay | 23/9/2025 | 17/6/2026 | A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file is processed, the program incorrectly handles memory in the checksum calculation logic at do_checksum_math_liveplay in tcpliveplay.c, leading to a possible denial of service. | |
| Analizada | Alta (7.8) | 0.18% | — | Broadcom Tcpreplay | 22/9/2025 | 17/6/2026 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a… | |
| Aplazada | Alta (7) | 0.23% | — | Broadcom SOCAICalix Gigacenter ONTAI | 9/9/2025 | 30/9/2026 | Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G. | |
| Analizada | Baja (1.9) | 0.25% | — | Broadcom Tcpreplay | 29/8/2025 | 17/6/2026 | A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 4.5.3-beta3 is… | |
| Analizada | Baja (1.9) | 0.24% | — | Broadcom Tcpreplay | 24/8/2025 | 17/6/2026 | A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Baja (1.9) | 0.24% | — | Broadcom Tcpreplay | 24/8/2025 | 17/6/2026 | A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fix_ipv6_checksums of the file edit_packet.c of the component tcprewrite. This manipulation causes use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to… | |
| Analizada | Baja (1.9) | 0.25% | — | Broadcom Tcpreplay | 24/8/2025 | 17/6/2026 | A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version… | |
| Aplazada | Baja (1.9) | 0.15% | — | Broadcom TcpreplayAI | 19/8/2025 | 17/6/2026 | A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been… | |
| Analizada | Baja (1.3) | 1.00% | — | Broadcom Tcpreplay | 15/8/2025 | 17/6/2026 | A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be… | |
| Analizada | Media (4.6) | 0.19% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user. | |
| Analizada | Media (5.6) | 0.30% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed. | |
| Analizada | Alta (8.6) | 0.17% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036. |