Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.25% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure. | |
| Analizada | Media (6.7) | 0.14% | — | Broadcom Brocade Sannav | 10/7/2025 | 17/6/2026 | Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host… | |
| Analizada | Media (5.1) | 0.14% | — | Broadcom Brocade Sannav | 10/7/2025 | 17/6/2026 | Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are… | |
| Analizada | Media (5.1) | 0.14% | — | Broadcom Brocade Sannav | 10/7/2025 | 17/6/2026 | Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server VM’s audit logs and are not controlled… | |
| Analizada | Media (6.8) | 0.33% | — | Broadcom Fabric Operating System | 8/7/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when supportsave is invoked remotely, using ssh command or SANnav inline ssh, and the… | |
| Analizada | Media (6.7) | 0.21% | — | Broadcom Rabbitmq Server | 19/6/2025 | 17/6/2026 | RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded… | |
| Analizada | Media (4.8) | 0.21% | — | Broadcom Fabric Operating System | 19/6/2025 | 17/6/2026 | A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit | |
| Analizada | Media (5.9) | 0.26% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. | |
| Analizada | Media (6.9) | 0.31% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. | |
| Analizada | Alta (7.5) | 0.34% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. | |
| Analizada | Alta (7.5) | 0.42% | — | Broadcom Tcpreplay | 29/5/2025 | 17/6/2026 | tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c. | |
| Aplazada | Alta (8.5) | 0.59% | 💥 Exploit | Broadcom Automic Automation Agent UnixAI | 20/5/2025 | 17/6/2026 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges. | |
| Analizada | Crítica (9.4) | 0.50% | — | Broadcom BitnamiBroadcom Bitnami/pgpool | 13/5/2025 | 17/6/2026 | The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes,… | |
| Analizada | Alta (7.5) | 0.29% | — | Broadcom Symantec Eraser Engine | 30/4/2025 | 17/6/2026 | Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user. | |
| Analizada | Alta (8.6) | 0.69% | ⚠ Explotación activa | Broadcom Fabric Operating System | 24/4/2025 | 17/6/2026 | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6. | |
| Analizada | Alta (7.6) | 0.37% | — | Broadcom Brocade Active Support Connectivity Gateway | 28/2/2025 | 17/6/2026 | Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens… | |
| Analizada | Media (5.3) | 0.16% | — | Broadcom Fabric Operating System | 15/2/2025 | 17/6/2026 | If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An… | |
| Analizada | Alta (8.6) | 0.45% | — | Broadcom Fabric Operating System | 15/2/2025 | 17/6/2026 | Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the… | |
| Analizada | Alta (8.2) | 0.29% | — | Broadcom Brocade Sannav | 15/2/2025 | 17/6/2026 | Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22. | |
| Analizada | Media (6.9) | 0.20% | — | Broadcom Brocade Sannav | 15/2/2025 | 17/6/2026 | Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, an attacker can read Brocade SANnav data stream that includes monitored Brocade Fabric OS switches performance data, port status, zoning information, WWNs, IP Addresses, but no customer data, no… | |
| Analizada | Alta (8.6) | 0.51% | — | Broadcom Brocade Sannav | 14/2/2025 | 17/6/2026 | Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authenticated attacker to execute various attacks. | |
| Analizada | Alta (8.6) | 0.16% | — | Broadcom Brocade Sannav | 14/2/2025 | 17/6/2026 | Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav. | |
| Analizada | Media (4.4) | 0.11% | — | Broadcom Brocade Sannav | 14/2/2025 | 17/6/2026 | CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges could retrieve sensitive information including… | |
| Analizada | Alta (8.5) | 0.62% | — | Broadcom Fabric Operating System | 21/11/2024 | 17/6/2026 | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade… | |
| Analizada | Media (5.9) | 0.65% | — | Broadcom Fabric Operating System | 21/11/2024 | 17/6/2026 | Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave. |