Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)1.3%—Managed Ethernet SwitchAI16/6/202617/6/2026
Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.
AplazadaNinguna (0)0.18%—Moxa Ethernet SwitchesAI23/10/202517/6/2026
An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service.…
AplazadaMedia (4.8)0.33%—Moxa Ethernet SwitchesAI23/10/202517/6/2026
Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classified as stored…
AplazadaAlta (8.3)0.34%—Cisco IOS SoftwareAICisco Industrial Ethernet Switch Device ManagerAI7/5/202517/6/2026
A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker could exploit this vulnerability by sending…
AplazadaCrítica (9.2)0.85%—Moxa Ethernet SwitchAI15/1/202517/6/2026
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess…
ModificadaBaja (3.7)4.9%—OpensslCanonical Ubuntu LinuxDebian LinuxOracle JD Edwards World Security+119/9/202017/6/2026
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent…
ModificadaCrítica (10)1.6%—Redlion Sixnet-managed Industrial Switches FirmwareRedlion Stride-managed Ethernet Switches Firmware9/5/201817/6/2026
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190. Vulnerable versions of Stride-Managed Ethernet switches and Sixnet-Managed Industrial switches use…
ModificadaMedia (6.5)58%—Oracle Supply Chain Products SuiteOracle JD Edwards Enterpriseone ToolsOpensslOracle Opus 10G Ethernet Switch Family9/7/201517/6/2026
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended…
ModificadaAlta (7)1.9%—HP 3com RouterHP 5500-24g-4sfp HI Switch With 2 Interface SlotsHP 5500-24g-poe EI SwitchHP 5500-24g-poe SI Switch+1312/8/201316/6/2026
The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the…
ModificadaAlta (7.1)3.1%—HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+116/7/201316/6/2026
Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors.
ModificadaAlta (10)10%—HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+116/7/201316/6/2026
Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors.
ModificadaAlta (7.5)1.5%—Asante Fm2008 Managed Ethernet Switch15/12/200416/6/2026
Asante FM2008 running firmware 1.06 is shipped with a default username and password, which could allow remote attackers to gain unauthorized access.
ModificadaAlta (7.5)1.3%—Asante Fm2008 Managed Ethernet Switch15/12/200416/6/2026
The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access.