Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

425 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.95%—Sourcefabric Phoniebox29/8/202417/6/2026
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php
AnalizadaCrítica (9.8)0.95%—Sourcefabric Phoniebox29/8/202417/6/2026
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php
AnalizadaCrítica (9.8)0.95%—Sourcefabric Phoniebox29/8/202417/6/2026
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php
AnalizadaCrítica (9.8)0.95%—Sourcefabric Phoniebox29/8/202417/6/2026
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php
ModificadaMedia (5.3)0.59%💥 PoCHyperledger Fabric25/8/202417/6/2026
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
AplazadaAlta (8.7)15%—Sourcefabric PhonieboxAI10/7/202417/6/2026
Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will…
AplazadaAlta (8.7)0.48%—Sourcefabric PhonieboxAI10/7/202417/6/2026
Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will…
ModificadaCrítica (9)15%💥 PoCFreeradiusBroadcom Brocade SannavBroadcom Fabric Operating SystemSonicwall Sonicos9/7/202417/6/2026
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
AnalizadaAlta (8.1)0.54%—Broadcom Fabric Operating System26/6/202417/6/2026
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the…
ModificadaMedia (5.5)0.11%—Broadcom Fabric Operating System26/6/202417/6/2026
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is…
AnalizadaMedia (4.3)0.30%—Broadcom Fabric Operating System26/6/202417/6/2026
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
AplazadaMedia (6.9)0.20%—HPE FlexfabricAIHPE FlexnetworkAI15/4/202417/6/2026
A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to gain privileged access to switches resulting in information disclosure.
AnalizadaMedia (6.2)0.89%—Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+39/4/202417/6/2026
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
ModificadaMedia (4.3)0.18%—Broadcom Fabric Operating System5/4/202417/6/2026
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
AnalizadaMedia (6.3)2.9%—Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.
ModificadaAlta (7.3)3.9%💥 PoCApache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
ModificadaCrítica (9.8)1.2%—Broadcom Fabric Operating System4/4/202417/6/2026
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.
AnalizadaAlta (7.5)0.80%—Cisco Nexus Dashboard Fabric Controller3/4/202417/6/2026
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through…
AnalizadaAlta (8.8)0.26%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator3/4/202417/6/2026
A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the…
AnalizadaAlta (8.6)36%—Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+1027/3/202417/6/2026
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.…
AnalizadaAlta (7.4)0.35%—Danielmiessler Fabric18/3/202417/6/2026
danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.
ModificadaMedia (4.3)0.27%—Fabrick Gestpay FOR Woocommerce28/2/202417/6/2026
The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to missing or incorrect nonce validation on the 'ajax_unset_default_card' function. This makes it possible for unauthenticated attackers to remove the default status…
ModificadaMedia (4.3)0.27%—Fabrick Gestpay FOR Woocommerce28/2/202417/6/2026
The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to missing or incorrect nonce validation on the 'ajax_delete_card' function. This makes it possible for unauthenticated attackers to delete the default card token for…
ModificadaMedia (4.3)0.29%—Fabrick Gestpay FOR Woocommerce28/2/202417/6/2026
The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to missing or incorrect nonce validation on the 'ajax_set_default_card' function. This makes it possible for unauthenticated attackers to set the default card token…
AnalizadaCrítica (9.8)2.1%—Dell Smartfabric Os1015/2/202417/6/2026
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system takeover. This is a…