Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.69% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests. POC Step 1: Prepare the SSRF with a request like this: GET… | |
| Modificada | Crítica (9.8) | 1.4% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-12 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021,… | |
| Modificada | Crítica (9.8) | 0.37% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-12 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/6/2023 | 17/6/2026 | Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021,… | |
| Modificada | Media (6.1) | 0.52% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An… | |
| Modificada | Alta (7.5) | 0.95% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of… | |
| Modificada | Media (4.6) | 0.29% | — | Cisco Nexus 93180yc-fx3s FirmwareCisco Nexus 93180yc-fx3 FirmwareCisco UCS Central SoftwareCisco UCS 6536 Firmware+2 | 23/2/2023 | 17/6/2026 | A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability is due to the improper implementation of the password… | |
| Modificada | Alta (8.8) | 0.42% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 3.5% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via… | |
| Modificada | Media (4.3) | 0.64% | — | Nexusphp | 19/1/2023 | 17/6/2026 | Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page). | |
| Modificada | Media (5.4) | 60% | — | Nexusphp | 19/1/2023 | 17/6/2026 | A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject arbitrary web script or HTML via the title parameter used in /subtitles.php. | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Nexusphp | 19/1/2023 | 17/6/2026 | Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id… | |
| Modificada | Crítica (9.8) | 19% | — | Nexusphp | 19/1/2023 | 17/6/2026 | Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php. | |
| Modificada | Media (4.7) | 0.81% | — | Ieee 802.2Ietf P802.1qCisco Catalyst 6503-e FirmwareCisco Catalyst 6504-e Firmware+92 | 27/9/2022 | 17/6/2026 | Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. | |
| Modificada | Alta (8.8) | 0.40% | — | Cisco MDS 9506 FirmwareCisco MDS 9513 FirmwareCisco MDS 9706 FirmwareCisco MDS 9710 Firmware+140 | 25/8/2022 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input… | |
| Modificada | Alta (8.6) | 1.1% | — | Cisco Nexus 3016 FirmwareCisco Nexus 3016q FirmwareCisco Nexus 3048 FirmwareCisco Nexus 3064 Firmware+143 | 25/8/2022 | 17/6/2026 | A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 0.84% | — | Project-nexus Project Project-nexus | 20/8/2022 | 17/6/2026 | Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available. | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with Administrator credentials could exploit this… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.21% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.21% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Alta (8.8) | 0.60% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.4) | 0.55% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is… | |
| Modificada | Crítica (9.8) | 1.3% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 1.6% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. |