Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
931 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.67% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <… | |
| Aplazada | Media (5.9) | 0.28% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Media (5.3) | 0.52% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Alta (7.1) | 0.44% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Media (5.3) | 0.38% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xc316-8AISiemens Scalance Xc324-4AISiemens Scalance Xc332AI+15 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.1), SCALANCE XC332 (6GK5332-0GA00-2AC2)… | |
| Analizada | Media (5.9) | 0.26% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. | |
| Analizada | Media (6.9) | 0.31% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. | |
| Analizada | Alta (7.5) | 0.34% | — | Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/6/2025 | 17/6/2026 | VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. | |
| Analizada | Alta (7.5) | 0.42% | — | Broadcom Tcpreplay | 29/5/2025 | 17/6/2026 | tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c. | |
| Aplazada | Alta (8.5) | 0.59% | 💥 Exploit | Broadcom Automic Automation Agent UnixAI | 20/5/2025 | 17/6/2026 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges. | |
| Analizada | Media (6.5) | 0.19% | — | Cedcommerce Wholesale MarketCedcommerce Wholesale Market FOR Woocommerce | 16/5/2025 | 17/6/2026 | The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack | |
| Aplazada | Crítica (9.4) | 1.2% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <… | |
| Aplazada | Crítica (9.4) | 1.2% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <… | |
| Aplazada | Crítica (9.4) | 1.2% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <… | |
| Analizada | Crítica (9.4) | 0.50% | — | Broadcom BitnamiBroadcom Bitnami/pgpool | 13/5/2025 | 17/6/2026 | The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes,… | |
| Analizada | Alta (7.5) | 0.29% | — | Broadcom Symantec Eraser Engine | 30/4/2025 | 17/6/2026 | Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user. | |
| Aplazada | Alta (7.5) | 0.75% | — | Cedcommerce Product Lister FOR EbayAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce Product Lister for eBay product-lister-ebay allows PHP Local File Inclusion.This issue affects Product Lister for eBay: from n/a through <= 2.0.9. | |
| Analizada | Alta (8.6) | 0.69% | ⚠ Explotación activa | Broadcom Fabric Operating System | 24/4/2025 | 17/6/2026 | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6. | |
| Aplazada | Media (5.3) | 0.58% | — | Cedcommerce Ship PER ProductAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in cedcommerce Ship Per Product ship-per-product allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ship Per Product: from n/a through <= 2.1.0. | |
| Aplazada | Media (6.3) | 0.28% | — | Siemens Ruggedcom Rm1224 LTEAISiemens Scalance M804pbAISiemens Scalance M812-1AISiemens Scalance M816-1AI+15 | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.2.1), SCALANCE… | |
| Analizada | Alta (7.6) | 0.37% | — | Broadcom Brocade Active Support Connectivity Gateway | 28/2/2025 | 17/6/2026 | Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens… | |
| Aplazada | Media (6.9) | 2.7% | — | Bdcom Behavior Management AND Auditing SystemAI | 21/2/2025 | 17/6/2026 | A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code leads to os command injection. The attack… | |
| Analizada | Media (5.3) | 0.16% | — | Broadcom Fabric Operating System | 15/2/2025 | 17/6/2026 | If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An… | |
| Analizada | Alta (8.6) | 0.45% | — | Broadcom Fabric Operating System | 15/2/2025 | 17/6/2026 | Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the… | |
| Analizada | Alta (8.2) | 0.29% | — | Broadcom Brocade Sannav | 15/2/2025 | 17/6/2026 | Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22. |