Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
ModificadaAlta (7.5)0.83%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
ModificadaAlta (7.5)0.59%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
ModificadaAlta (7.5)0.60%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
ModificadaMedia (5.5)0.12%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
ModificadaAlta (7.5)0.59%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
ModificadaAlta (7.5)0.35%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows
ModificadaMedia (5.5)0.11%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
ModificadaAlta (7.5)0.40%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
ModificadaCrítica (9.8)0.70%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
ModificadaCrítica (9.8)0.71%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
ModificadaMedia (6.5)0.58%—Broadcom Raid Controller WEB Interface15/8/202317/6/2026
Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user
ModificadaAlta (7.5)1.0%—Tel-ster Telwin Scada Webinterface3/8/202317/6/2026
External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.
ModificadaMedia (5.4)0.32%—SAP Application Interface11/4/202317/6/2026
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the…
ModificadaMedia (4.3)0.41%—SAP Application Interface Framework11/4/202317/6/2026
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.
ModificadaMedia (5.4)0.32%—SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core11/4/202317/6/2026
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images…
ModificadaMedia (4.6)0.32%—SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core11/4/202317/6/2026
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the…
ModificadaMedia (5.4)0.60%—SAS WEB Administration Interface3/4/202317/6/2026
A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface (SASAdmin). For the product…