Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.40% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.3) | 0.25% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.2) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.2) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.9) | 1.2% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files which are not limited to the intended files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.5) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. To determine which BIG-IP platforms have an ePVA chip… | |
| Analizada | Alta (8.7) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 17/6/2026 | When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.44% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+19 | 15/10/2025 | 17/6/2026 | When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+19 | 15/10/2025 | 17/6/2026 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.5) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 30/9/2026 | A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note:… | |
| Analizada | Alta (7.5) | 0.32% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application. | |
| Analizada | Media (6.1) | 0.29% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking. | |
| Analizada | Alta (7.5) | 0.53% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information. | |
| Analizada | Alta (7.5) | 0.53% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information. | |
| Analizada | Media (6.5) | 0.36% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. | |
| Analizada | Crítica (9.8) | 0.49% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | |
| Analizada | Alta (7.5) | 0.43% | — | Sick Baggage AnalyticsSick Logistic Diagnostic AnalyticsSick Package AnalyticsSick Tire Analytics | 6/10/2025 | 17/6/2026 | Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering. | |
| Analizada | Alta (7.5) | 0.39% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | The application provides access to a login protected H2 database for caching purposes. The username is prefilled. | |
| Analizada | Alta (7.5) | 0.55% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged. | |
| Analizada | Media (4.3) | 0.33% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application. | |
| Analizada | Media (5.3) | 0.36% | — | Sick Enterprise Analytics | 6/10/2025 | 17/6/2026 | An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example. | |
| Analizada | Media (5.3) | 0.40% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Logistic Diagnostic AnalyticsSick Package Analytics+1 | 6/10/2025 | 17/6/2026 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration. |