Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
484 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.14% | — | Dell Data Domain Operating System | 8/11/2024 | 17/6/2026 | Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to unauthorized execution of certain commands to overwrite system config of the… | |
| Modificada | Alta (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 3/9/2024 | 17/6/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Modificada | Crítica (9) | 15% | 💥 PoC | FreeradiusBroadcom Brocade SannavBroadcom Fabric Operating SystemSonicwall Sonicos | 9/7/2024 | 17/6/2026 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. | |
| Modificada | Baja (3.5) | 0.30% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Alta (8.8) | 1.2% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's… | |
| Modificada | Media (6.5) | 0.48% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to temporary resource constraint of system… | |
| Modificada | Media (6.8) | 0.40% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the application sending over an unauthorized file to the managed system. | |
| Modificada | Baja (2.7) | 0.30% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the reuse of disclosed information to gain unauthorized access to the… | |
| Modificada | Alta (8.8) | 0.64% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Modificada | Media (5.9) | 0.26% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an weak cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to man-in-the-middle attack that exposes sensitive session information. | |
| Modificada | Media (4.4) | 0.20% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to… | |
| Analizada | Media (4.9) | 0.35% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to disclosure of information on the application or remote client. | |
| Analizada | Media (4.8) | 0.24% | — | Dell Data Domain Operating System | 26/6/2024 | 17/6/2026 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Stored Cross-Site Scripting Vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store.… | |
| Analizada | Alta (8.1) | 0.54% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the… | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is… | |
| Analizada | Media (4.3) | 0.30% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords. | |
| Modificada | Alta (7.8) | 0.26% | — | A10networks Advanced Core Operating System | 6/6/2024 | 17/6/2026 | A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of A10 Thunder ADC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (8.8) | 3.0% | — | A10networks Advanced Core Operating System | 6/6/2024 | 17/6/2026 | A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the CsrRequestView class.… | |
| Analizada | Alta (8.8) | 2.1% | — | A10networks Advanced Core Operating System | 3/5/2024 | 17/6/2026 | A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.5) | 2.5% | — | A10networks Advanced Core Operating System | 3/5/2024 | 17/6/2026 | A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Media (4.3) | 0.18% | — | Broadcom Fabric Operating System | 5/4/2024 | 17/6/2026 | Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display. | |
| Analizada | Media (6.3) | 2.9% | — | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. | |
| Modificada | Alta (7.3) | 3.9% | 💥 PoC | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | |
| Modificada | Crítica (9.8) | 1.2% | — | Broadcom Fabric Operating System | 4/4/2024 | 17/6/2026 | Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch. | |
| Analizada | Alta (8.6) | 36% | — | Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+10 | 27/3/2024 | 17/6/2026 | When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.… |