Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.16% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user. | |
| Aplazada | Alta (7.5) | 0.72% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory. | |
| Aplazada | Alta (7.2) | 0.88% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Modificada | Media (6.4) | 0.30% | — | Fabricators Vanilla OS Core Image | 13/1/2026 | 5/7/2026 | fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts. | |
| Analizada | Alta (7.5) | 0.53% | — | Sourcefabric Phoniebox | 18/12/2025 | 17/6/2026 | An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. This allows a remote,… | |
| Aplazada | Alta (8.1) | 0.50% | — | Ancorahemes FabricaAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Fabrica fabrica allows PHP Local File Inclusion.This issue affects Fabrica: from n/a through <= 1.8.1. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Fabric | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Fabric fabric allows PHP Local File Inclusion.This issue affects Fabric: from n/a through <= 1.5.0. | |
| Analizada | Alta (8.8) | 1.2% | — | Dell Smartfabric Os10 | 12/11/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (8.8) | 1.2% | — | Dell Smartfabric Os10 | 12/11/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Smartfabric Os10 | 12/11/2025 | 6/10/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (8.4) | 0.35% | — | Extremenetworks Fabric Engine (voss) | 7/10/2025 | 17/6/2026 | A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing… | |
| Modificada | Baja (2) | 0.70% | 💥 Exploit | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and… | |
| Analizada | Baja (2) | 0.31% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Executing manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was… | |
| Analizada | Baja (2) | 0.30% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/manageFilesFolders.php. Performing manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be… | |
| Analizada | Baja (2) | 0.30% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/cardEdit.php. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Baja (2) | 0.29% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A flaw has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/inc.setWlanIpMail.php. This manipulation of the argument Email address causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was… | |
| Analizada | Baja (2.1) | 9.4% | — | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/api/playlist/playsinglefile.php. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Baja (2.1) | 10% | 💥 Exploit | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Executing manipulation of the argument playlist can lead to os command injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 7.1% | — | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single.php. Performing manipulation of the argument playlist results in os command injection. The attack can be initiated remotely. The exploit has been released to the public… | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Smartfabric Os10 | 30/7/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.5) | 0.49% | — | Dell Smartfabric Os10 | 30/7/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (5.5) | 0.17% | — | Dell Smartfabric Os10 | 30/7/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Media (6.8) | 0.33% | — | Broadcom Fabric Operating System | 8/7/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when supportsave is invoked remotely, using ssh command or SANnav inline ssh, and the… | |
| Analizada | Media (6) | 0.36% | — | Microsoft Azure Service Fabric | 8/7/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (4.8) | 0.21% | — | Broadcom Fabric Operating System | 19/6/2025 | 17/6/2026 | A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit |