Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux | |
| Modificada | Alta (7.5) | 0.40% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities | |
| Modificada | Crítica (9.8) | 0.70% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers | |
| Modificada | Crítica (9.8) | 0.71% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup | |
| Modificada | Media (6.5) | 0.58% | — | Broadcom Raid Controller WEB Interface | 15/8/2023 | 17/6/2026 | Broadcom RAID Controller web interface is vulnerable client-side control bypass leads to unauthorized data access for low privileged user | |
| Modificada | Media (5.3) | 0.64% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauthenticated attacker to get technical details about the web interface. | |
| Modificada | Alta (7.1) | 0.16% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0. | |
| Modificada | Media (6.1) | 0.48% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application. | |
| Modificada | Alta (7.8) | 0.17% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could obtain root privileges in Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c and v9.2.0. | |
| Modificada | Media (5.5) | 0.28% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service. | |
| Modificada | Media (5.5) | 0.28% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service. | |
| Modificada | Media (5.5) | 0.18% | — | Broadcom Brocade Fabric Operating System | 2/8/2023 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep. | |
| Modificada | Alta (7.8) | 0.21% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names inside Brocade Fabric OS to execute any command regardless of assigned privilege. Starting with Fabric OS v9.1.0, “root” account access is disabled. | |
| Modificada | Media (6.5) | 0.66% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave. This could allow a remote authenticated attacker to access sensitive information. | |
| Modificada | Media (5.5) | 0.22% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands that can cause the content of shell interpreted… | |
| Modificada | Alta (7.8) | 0.27% | — | Broadcom Fabric Operating System | 1/8/2023 | 17/6/2026 | A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking the rbash shell. Starting with Fabric OS v9.1.0, “root” account access is disabled. | |
| Modificada | Alta (8.1) | 0.47% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. | |
| Modificada | Media (5.4) | 0.34% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability. | |
| Modificada | Alta (7.8) | 0.19% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. | |
| Modificada | Media (5.4) | 3.1% | 💥 Exploit | Broadcom Symantec Siteminder Webagent | 30/5/2023 | 17/6/2026 | A user can supply malicious HTML and JavaScript code that will be executed in the client browser | |
| Modificada | Media (6.1) | 0.47% | — | Broadcom Vmware Nsx-t Data Center | 26/5/2023 | 17/6/2026 | NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages. |