Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
931 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 32% | ⚠ Explotación activa | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 6/5/2026 | 17/6/2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this… | |
| Aplazada | Baja (1.9) | 0.34% | — | Bdcom P3310dAI | 25/4/2026 | 17/6/2026 | A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. The vendor was… | |
| Aplazada | Baja (1.9) | 0.34% | — | Bdcom P3310dAI | 25/4/2026 | 17/6/2026 | A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and… | |
| Aplazada | Baja (1.9) | 0.34% | — | Bdcom P3310dAI | 25/4/2026 | 17/6/2026 | A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (1.9) | 0.34% | — | Bdcom P3310dAI | 25/4/2026 | 17/6/2026 | A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipulation of the argument User name results in cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Pendiente de análisis | Alta (8.7) | 0.42% | — | Siemens Ruggedcom Crossbow Secure Access Manager PrimaryAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device… | |
| Analizada | Media (4.6) | 0.24% | — | Broadcom Symantec Siteminder | 10/3/2026 | 17/6/2026 | Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page. | |
| Analizada | Alta (8.3) | 0.40% | — | Broadcom Brocade Active Support Connectivity Gateway | 3/3/2026 | 17/6/2026 | Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric. | |
| Aplazada | Media (5.5) | 0.15% | — | Broadcom TcpreplayAI | 10/2/2026 | 17/6/2026 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function at src/tcpedit/plugins/dlt_utils.c. | |
| Analizada | Alta (8.5) | 0.14% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands. | |
| Analizada | Media (4.6) | 0.20% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories. | |
| Analizada | Media (4.6) | 0.20% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories. | |
| Analizada | Alta (8.2) | 0.22% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command. | |
| Analizada | Alta (8.4) | 0.55% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security controls allowing the execution of arbitrary commands. | |
| Analizada | Alta (8.5) | 0.65% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command. | |
| Analizada | Media (6) | 0.16% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user. | |
| Analizada | Media (4.6) | 0.20% | — | Broadcom Sannav | 3/2/2026 | 17/6/2026 | A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such as details of database tables and… | |
| Analizada | Alta (7.1) | 0.37% | — | Broadcom Sannav | 3/2/2026 | 17/6/2026 | A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database password in the system audit logs. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the Brocade SANnav database password. | |
| Analizada | Alta (8.5) | 0.29% | — | Broadcom Sannav | 2/2/2026 | 17/6/2026 | Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM occurs on a Brocade SANnav server, the call stack trace for the Brocade switch is also collected in the heap dump file which contains this switch password in clear text. The vulnerability could allow… | |
| Analizada | Media (6) | 0.25% | — | Broadcom Sannav | 2/2/2026 | 17/6/2026 | Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the database password. | |
| Analizada | Alta (7.1) | 0.16% | — | Broadcom Sannav | 2/2/2026 | 17/6/2026 | A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered during a migration and… | |
| Analizada | Crítica (9.8) | 86% | ⚠ Explotación activa | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortinac-fFortinet Fortiproxy+3 | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9,… | |
| Analizada | Crítica (9.8) | 3.9% | ⚠ Explotación activa | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortisaseSiemens Ruggedcom Ape1808 Firmware | 13/1/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized… | |
| Analizada | Baja (2.3) | 0.30% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Alta (7.1) | 0.14% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier. |