Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

3326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.19%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.
ModificadaCrítica (9.8)1.3%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
AnalizadaCrítica (9.8)88%⚠ Explotación activa💥 ExploitBarracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+124/5/202317/6/2026
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete…
ModificadaCrítica (9.8)0.75%—Oretnom23 Employee AND Visitor Gate Pass Logging System23/5/202317/6/2026
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
ModificadaAlta (8.1)0.36%—Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Loggregator-agent19/5/202317/6/2026
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the…
ModificadaAlta (7.5)2.4%💥 PoCFastweb Fastgate Vdsl2 Dga4131fwb FirmwareFastweb Fastgate Gpon Fga2130fwb Firmware19/5/202317/6/2026
Un desbordamiento de búfer en un servicio de red en Fastweb FASTGate MediaAccess FGA2130FWB, versión de firmware 18.3.n.0482_FW_230_FGA2130 y DGA4131FWB, versión de firmware hasta 18.3.n.0462_FW_261_DGA4131, permite a un atacante remoto reiniciar el dispositivo a través de una solicitud HTTP manipulada, provocando DoS.
ModificadaMedia (6.1)0.38%—Woocommerce Jazzcash Gateway9/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in JC Development Team WooCommerce JazzCash Gateway Plugin plugin <= 2.0 versions.
ModificadaCrítica (9.8)0.90%—Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce8/5/202317/6/2026
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
ModificadaAlta (7.5)0.56%—Netentsec Application Security Gateway5/5/20239/7/2026
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
ModificadaCrítica (9.8)0.63%—Netentsec Application Security Gateway5/5/20239/7/2026
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
ModificadaAlta (7.8)0.28%—Illumos-gate4/5/202317/6/2026
illumos illumos-gate antes de 676abcb tiene un Desbordamiento de Búfer en /dev/net, lo que lleva a la escalada de privilegios a través de una estadística en un nombre de archivo largo en /dev/net.
ModificadaAlta (7.5)0.62%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (4.3)1.2%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which…
ModificadaMedia (6.1)0.39%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (5.3)0.56%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+163/5/202317/6/2026
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (7.5)0.75%—Progress Flowmon Packet Investigator21/4/202317/6/2026
In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vulnerability to retrieve files on the Flowmon appliance's local filesystem.
ModificadaMedia (5.3)0.47%—Stargate-bukkit Project Stargate-bukkit19/4/202317/6/2026
Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Minecarts with chests will drop their items when teleporting through a portal; when they reappear, they will still have their items impacting the integrity of the game world. The teleport code has since…
ModificadaMedia (4.9)0.52%—Secomea Gatemanager19/4/202317/6/2026
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.
ModificadaAlta (8.8)0.17%—Secomea Gatemanager19/4/202317/6/2026
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.
ModificadaAlta (8.8)0.66%—Schneider-electric Insighthome FirmwareSchneider-electric Insightfacility FirmwareSchneider-electric Conext Gateway Firmware18/4/202317/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
ModificadaBaja (3.7)1.0%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability…
ModificadaMedia (5.9)1.5%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows…
ModificadaMedia (5.9)1.4%—Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows…
ModificadaMedia (5.3)2.5%💥 PoCOracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows…
ModificadaBaja (3.7)1.2%—Oracle GraalvmOracle JDKOracle JREDebian Linux+618/4/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Difficult to exploit vulnerability…