Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2649▼ 259 respecto a la semana anterior
Críticas / altas1356▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)1.8%—Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+14223/9/202117/6/2026
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory…
ModificadaMedia (6.5)2.3%—Fronius Datamanager BOX 2.0 FirmwareFronius ECO 25.0-3-s FirmwareFronius ECO 27.0-3-s FirmwareFronius Galvo 1.5-1 Firmware+624/12/201917/6/2026
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
ModificadaCrítica (9.8)1.9%—Fronius Datamanager BOX 2.0 FirmwareFronius ECO 25.0-3-s FirmwareFronius ECO 27.0-3-s FirmwareFronius Galvo 1.5-1 Firmware+624/12/201917/6/2026
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
ModificadaAlta (7.5)1.5%—Siteminder Agent FOR Sharepoint 2010Siteminder Federation 12.0Siteminder Federation 12.1Siteminder Federation 12.5+421/3/201316/6/2026
CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.