Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
931 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.77% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M826-2 Shdsl-router Firmware+22 | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1… | |
| Modificada | Media (6.8) | 0.30% | — | Broadcom Symantec Privileged Access Management | 15/7/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI. | |
| Modificada | Crítica (9) | 15% | 💥 PoC | FreeradiusBroadcom Brocade SannavBroadcom Fabric Operating SystemSonicwall Sonicos | 9/7/2024 | 17/6/2026 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. | |
| Aplazada | Alta (8.7) | 0.28% | — | Siemens Ruggedcom Rmc30AISiemens Ruggedcom Rmc30ncAISiemens Ruggedcom Rp110AISiemens Ruggedcom Rp110ncAI+20 | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.10), RUGGEDCOM RP110 (All versions < V4.3.10), RUGGEDCOM RP110NC (All versions < V4.3.10), RUGGEDCOM RS400 (All versions < V4.3.10), RUGGEDCOM RS400NC (All versions < V4.3.10), RUGGEDCOM RS401 (All… | |
| Aplazada | Alta (7.5) | 0.34% | — | Siemens Ruggedcom Rmc8388AISiemens Ruggedcom Rmc8388ncAISiemens Ruggedcom Rs416ncv2AISiemens Ruggedcom Rs416pncv2AI+30 | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.9.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.9.0), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416v2 V5.X (All… | |
| Aplazada | Baja (2.3) | 0.35% | — | Siemens Ruggedcom Rst2228AISiemens Ruggedcom Rst2228pAI | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2228 (All versions < V5.9.0), RUGGEDCOM RST2228P (All versions < V5.9.0). The web server of the affected systems leaks the MACSEC key in clear text to a logged in user. An attacker with the credentials of a low privileged user could retrieve the MACSEC key and access… | |
| Modificada | Media (5.4) | 0.30% | — | Cedcommerce ONE Click Order Re-order | 4/7/2024 | 17/6/2026 | The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (4.3) | 0.33% | — | Trustedcomputinggroup Tpm2 Software StackAI | 28/6/2024 | 17/6/2026 | This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the… | |
| Analizada | Alta (8.1) | 0.54% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the… | |
| Modificada | Media (5.5) | 0.11% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is… | |
| Analizada | Media (4.3) | 0.30% | — | Broadcom Fabric Operating System | 26/6/2024 | 17/6/2026 | A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords. | |
| Analizada | Media (5.3) | 0.57% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a specific client under certain circumstances. An attacker could leverage this vulnerability to forward log messages to a specific compromised client. | |
| Analizada | Media (6.5) | 0.91% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the installation directory of the affected systems. The filename for the target file can be specified, thus arbitrary files can be overwritten by an attacker with the required… | |
| Analizada | Alta (7.2) | 1.4% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code… | |
| Analizada | Alta (7.2) | 1.4% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.3% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution. | |
| Analizada | Alta (7.5) | 0.69% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system, causing a denial of service situation. | |
| Analizada | Alta (8.8) | 0.78% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole database. | |
| Analizada | Alta (8.8) | 0.78% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database. | |
| Analizada | Crítica (9.8) | 0.79% | — | Siemens Ruggedcom Crossbow | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges. | |
| Analizada | Alta (7.8) | 0.16% | — | Broadcom Brocade Sannav | 8/5/2024 | 17/6/2026 | The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database. | |
| Analizada | Alta (7.2) | 0.85% | — | Broadcom Brocade Sannav | 27/4/2024 | 17/6/2026 | By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account. | |
| Analizada | Crítica (9.8) | 0.59% | — | Broadcom Brocade Sannav | 25/4/2024 | 17/6/2026 | A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against the Brocade SANnav. | |
| Analizada | Alta (7.5) | 0.47% | — | Broadcom Brocade Sannav | 25/4/2024 | 17/6/2026 | In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information. | |
| Analizada | Media (5.3) | 0.52% | — | Broadcom Brocade Sannav | 25/4/2024 | 17/6/2026 | Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated attacker to sniff the SANnav Docker information. |