Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

931 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.67%—Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+710/6/202517/6/2026
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <…
AplazadaMedia (5.9)0.28%—Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+310/6/202517/6/2026
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All…
AplazadaMedia (5.3)0.52%—Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+310/6/202517/6/2026
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All…
AplazadaAlta (7.1)0.44%—Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+310/6/202517/6/2026
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All…
AplazadaMedia (5.3)0.38%—Siemens Ruggedcom Rst2428pAISiemens Scalance Xc316-8AISiemens Scalance Xc324-4AISiemens Scalance Xc332AI+1510/6/202517/6/2026
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.1), SCALANCE XC332 (6GK5332-0GA00-2AC2)…
AnalizadaMedia (5.9)0.26%—Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform4/6/202517/6/2026
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
AnalizadaMedia (6.9)0.31%—Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform4/6/202517/6/2026
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
AnalizadaAlta (7.5)0.34%—Broadcom Vmware NSXVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform4/6/202517/6/2026
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
AnalizadaAlta (7.5)0.42%—Broadcom Tcpreplay29/5/202517/6/2026
tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
AplazadaAlta (8.5)0.59%💥 ExploitBroadcom Automic Automation Agent UnixAI20/5/202517/6/2026
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
AnalizadaMedia (6.5)0.19%—Cedcommerce Wholesale MarketCedcommerce Wholesale Market FOR Woocommerce16/5/202517/6/2026
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
AplazadaCrítica (9.4)1.2%—Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+713/5/202517/6/2026
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <…
AplazadaCrítica (9.4)1.2%—Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+713/5/202517/6/2026
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <…
AplazadaCrítica (9.4)1.2%—Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+713/5/202517/6/2026
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <…
AnalizadaCrítica (9.4)0.50%—Broadcom BitnamiBroadcom Bitnami/pgpool13/5/202517/6/2026
The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes,…
AnalizadaAlta (7.5)0.29%—Broadcom Symantec Eraser Engine30/4/202517/6/2026
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
AplazadaAlta (7.5)0.75%—Cedcommerce Product Lister FOR EbayAI24/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce Product Lister for eBay product-lister-ebay allows PHP Local File Inclusion.This issue affects Product Lister for eBay: from n/a through <= 2.0.9.
AnalizadaAlta (8.6)0.69%⚠ Explotación activaBroadcom Fabric Operating System24/4/202517/6/2026
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
AplazadaMedia (5.3)0.58%—Cedcommerce Ship PER ProductAI1/4/202517/6/2026
Missing Authorization vulnerability in cedcommerce Ship Per Product ship-per-product allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ship Per Product: from n/a through <= 2.1.0.
AplazadaMedia (6.3)0.28%—Siemens Ruggedcom Rm1224 LTEAISiemens Scalance M804pbAISiemens Scalance M812-1AISiemens Scalance M816-1AI+1511/3/202517/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.2.1), SCALANCE…
AnalizadaAlta (7.6)0.37%—Broadcom Brocade Active Support Connectivity Gateway28/2/202517/6/2026
Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens…
AplazadaMedia (6.9)2.7%—Bdcom Behavior Management AND Auditing SystemAI21/2/202517/6/2026
A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code leads to os command injection. The attack…
AnalizadaMedia (5.3)0.16%—Broadcom Fabric Operating System15/2/202517/6/2026
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An…
AnalizadaAlta (8.6)0.45%—Broadcom Fabric Operating System15/2/202517/6/2026
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the…
AnalizadaAlta (8.2)0.29%—Broadcom Brocade Sannav15/2/202517/6/2026
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.