Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Denial of Service in the RIM (Radio Interface Module) process running on the WiNG Access Point via crafted packets. | |
| Modificada | Alta (7.5) | 1.3% | — | Extremenetworks Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Stack Overflow in the RIM (Radio Interface Module) process running on the WiNG Access Point via crafted packets. | |
| Modificada | Alta (7.2) | 4.4% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.8) | 0.56% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (8.1) | 1.0% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values. | |
| Modificada | Media (6.7) | 0.37% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell. | |
| Modificada | Media (6.7) | 0.32% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process. | |
| Modificada | Media (6.7) | 0.27% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell. | |
| Modificada | Alta (7.5) | 1.3% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot. | |
| Modificada | Media (4.4) | 0.34% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files. | |
| Modificada | Media (4.4) | 0.35% | — | IBM Websphere Extreme Scale | 8/2/2017 | 17/6/2026 | IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sensitive information. | |
| Modificada | Baja (3.7) | 1.1% | — | IBM Websphere Extreme Scale | 2/7/2016 | 17/6/2026 | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | IBM Websphere Extreme Scale | 2/7/2016 | 17/6/2026 | CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. | |
| Modificada | Media (6.8) | 1.1% | — | Buffalotech Airstation Extreme N600 FirmwareBuffalotech Airstation Extreme N600 | 27/12/2015 | 17/6/2026 | Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 1.4% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. | |
| Modificada | Baja (2.1) | 0.50% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. | |
| Modificada | Media (6) | 0.54% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Websphere Extreme Scale | 4/10/2015 | 17/6/2026 | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |
| Modificada | Media (5) | 1.2% | — | IBM Websphere Extreme Scale | 3/8/2015 | 17/6/2026 | Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Websphere Extreme Scale Client | 22/2/2014 | 17/6/2026 | IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container. | |
| Modificada | Media (5.4) | 1.2% | — | Extremenetworks Exos | 23/1/2014 | 17/6/2026 | The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet… | |
| Modificada | Media (4.9) | 0.95% | — | IBM Websphere Extreme Scale | 16/10/2013 | 16/6/2026 | The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to conduct phishing attacks via unspecified vectors. |