Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
931 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.23% | — | Broadcom SOCAICalix Gigacenter ONTAI | 9/9/2025 | 30/9/2026 | Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G. | |
| Analizada | Baja (2.3) | 0.18% | — | Siemens Ruggedcom Rst2428p Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This could allow an unauthenticated attacker to access sensitive data, potentially leading to a breach of confidentiality. | |
| Analizada | Baja (2.3) | 0.18% | — | Siemens Ruggedcom Rst2428p Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to high volumes of query requests. This could allow an attacker to cause a temporary denial of service, with the system recovering once the activity… | |
| Analizada | Baja (1.9) | 0.25% | — | Broadcom Tcpreplay | 29/8/2025 | 17/6/2026 | A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 4.5.3-beta3 is… | |
| Analizada | Baja (1.9) | 0.24% | — | Broadcom Tcpreplay | 24/8/2025 | 17/6/2026 | A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Baja (1.9) | 0.24% | — | Broadcom Tcpreplay | 24/8/2025 | 17/6/2026 | A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fix_ipv6_checksums of the file edit_packet.c of the component tcprewrite. This manipulation causes use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to… | |
| Analizada | Baja (1.9) | 0.25% | — | Broadcom Tcpreplay | 24/8/2025 | 17/6/2026 | A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version… | |
| Aplazada | Baja (1.9) | 0.15% | — | Broadcom TcpreplayAI | 19/8/2025 | 17/6/2026 | A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been… | |
| Analizada | Baja (1.3) | 1.00% | — | Broadcom Tcpreplay | 15/8/2025 | 17/6/2026 | A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be… | |
| Aplazada | Alta (8.6) | 0.24% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (All versions), RUGGEDCOM ROX RX1500 (All versions), RUGGEDCOM ROX RX1501 (All versions), RUGGEDCOM ROX RX1510 (All versions), RUGGEDCOM ROX RX1511 (All versions), RUGGEDCOM ROX… | |
| Aplazada | Media (5.1) | 0.29% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (All versions), RUGGEDCOM ROX RX1500 (All versions), RUGGEDCOM ROX RX1501 (All versions), RUGGEDCOM ROX RX1510 (All versions), RUGGEDCOM ROX RX1511 (All versions), RUGGEDCOM ROX… | |
| Analizada | Media (4.6) | 0.19% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user. | |
| Analizada | Media (5.6) | 0.30% | — | Broadcom Symantec PGP Encryption | 11/8/2025 | 17/6/2026 | Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed. | |
| Analizada | Baja (1.9) | 0.21% | — | Xmlsoft Libxml2Siemens Ruggedcom Rst2428p FirmwareIBM ViosIBM AIX | 8/8/2025 | 1/7/2026 | A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Cedcommerce Refund AND Exchange With RMAAI | 18/7/2025 | 17/6/2026 | The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible… | |
| Analizada | Alta (8.6) | 0.17% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036. | |
| Analizada | Alta (7.1) | 0.25% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure. | |
| Analizada | Alta (7.2) | 71% | 💥 Exploit | SqliteApple IpadosApple Iphone OSApple Macos+5 | 15/7/2025 | 26/6/2026 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. | |
| Analizada | Media (6.7) | 0.14% | — | Broadcom Brocade Sannav | 10/7/2025 | 17/6/2026 | Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec commands. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host… | |
| Analizada | Media (5.1) | 0.14% | — | Broadcom Brocade Sannav | 10/7/2025 | 17/6/2026 | Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit logs are the local server VM’s audit logs and are not controlled by SANnav. These logs are only visible to the server admin of the host server and are… | |
| Analizada | Media (5.1) | 0.14% | — | Broadcom Brocade Sannav | 10/7/2025 | 17/6/2026 | Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the command line or while providing the passphrase through a temporary file. These audit logs are the local server VM’s audit logs and are not controlled… | |
| Analizada | Media (6.8) | 0.33% | — | Broadcom Fabric Operating System | 8/7/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when supportsave is invoked remotely, using ssh command or SANnav inline ssh, and the… | |
| Aplazada | Alta (7.7) | 0.24% | — | Siemens Ruggedcom Rmc8388AISiemens Ruggedcom Rmc8388ncAISiemens Ruggedcom Rs416ncv2AISiemens Ruggedcom Rs416pncv2AI+30 | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.10.0), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416v2 V5.X (All… | |
| Analizada | Media (6.7) | 0.21% | — | Broadcom Rabbitmq Server | 19/6/2025 | 17/6/2026 | RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded… | |
| Analizada | Media (4.8) | 0.21% | — | Broadcom Fabric Operating System | 19/6/2025 | 17/6/2026 | A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit |