Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.15% | — | Dell Smartfabric Os10 | 12/11/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.69% | — | Dell Smartfabric Os10 | 12/11/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Baja (3.3) | 0.15% | — | Dell Smartfabric Os10 | 12/11/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Alta (7.8) | 0.20% | — | Dell Smartfabric Os10 | 12/11/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution | |
| Aplazada | Alta (7.1) | 0.27% | — | YES WE Work Fabrica Synced Pattern InstancesAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yes We Work Fabrica Synced Pattern Instances fabrica-reusable-block-instances allows Reflected XSS.This issue affects Fabrica Synced Pattern Instances: from n/a through <= 1.0.8. | |
| Analizada | Alta (8.8) | 0.77% | — | Cisco Nexus Dashboard Fabric Controller | 6/11/2024 | 17/6/2026 | A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. | |
| Analizada | Media (6.6) | 1.1% | — | Microsoft Azure Service Fabric | 8/10/2024 | 17/6/2026 | Azure Service Fabric for Linux Remote Code Execution Vulnerability | |
| Analizada | Alta (8.6) | 0.29% | — | Cisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could… | |
| Analizada | Alta (8.6) | 0.29% | — | Cisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log… | |
| Analizada | Media (5.4) | 0.45% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an affected device. This vulnerability exists because of missing authorization controls on the affected REST API endpoint. An attacker could exploit this… | |
| Analizada | Alta (8.8) | 0.95% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device. This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol… | |
| Analizada | Alta (8.6) | 0.12% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of sensitive information within config only and full… | |
| Analizada | Media (5.5) | 0.76% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. This vulnerability is due to insufficient validation… | |
| Analizada | Media (5.4) | 0.36% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this… | |
| Analizada | Media (6.5) | 0.49% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.36% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending… | |
| Analizada | Alta (8.8) | 1.1% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of… | |
| Analizada | Alta (8.8) | 0.91% | — | Dell Smartfabric Os10 | 26/9/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability leading to code execution. | |
| Analizada | Alta (7.5) | 0.42% | — | Dell Smartfabric Os10 | 26/9/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to a denial of service. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Bravura Security FabricAI | 18/9/2024 | 17/6/2026 | An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5.x before 12.5.2.35950, 12.6.x before 12.6.2.37183, and 12.7.x before 12.7.1.38241. An unauthenticated attacker can cause a resource leak by issuing multiple failed login attempts through API SOAP. | |
| Modificada | Alta (8.1) | 0.28% | — | Dell Smartfabric Os10 | 6/9/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure. | |
| Analizada | Alta (8.8) | 1.2% | — | Dell Smartfabric Os10 | 6/9/2024 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Modificada | Alta (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 3/9/2024 | 17/6/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php |