Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.7)0.55%—Netgear Fs752tp FirmwareNetgear Gs108t FirmwareNetgear Gs110tp FirmwareNetgear Gs418tpp Firmware+2129/4/202017/6/2026
Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP 6.6.2.6 and earlier, GS716Tv2 5.4.2.27 and…
ModificadaMedia (5.9)1.7%—Huawei S9300 FirmwareHuawei S9300e FirmwareHuawei S7700 FirmwareHuawei S9700 Firmware+88/1/201817/6/2026
Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
ModificadaMedia (5.3)1.1%—Huawei S3300 Firmware22/11/201717/6/2026
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed packets and send them to a device to cause EFM flapping.
ModificadaAlta (7.5)0.94%—Huawei S2300 FirmwareHuawei S2700 FirmwareHuawei S3300 FirmwareHuawei S3700 Firmware+188/6/201717/6/2026
The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message.
ModificadaAlta (7.5)0.74%—Huawei Campus S3700hi FirmwareHuawei S5700 FirmwareHuawei S6700 FirmwareHuawei S3300hi Firmware+102/4/201717/6/2026
Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S2350 with software V200R003C00SPC300; S2750 with software…
ModificadaAlta (7.5)1.0%—Huawei S9300 FirmwareHuawei S3300 FirmwareHuawei S2300 FirmwareHuawei S5300 Firmware+12/4/201717/6/2026
Huawei S9300 with software before V100R006SPH013 and S2300,S3300,S5300,S6300 with software before V100R006SPH010 support Y.1731 and therefore have the Y.1731 vulnerability in processing special packets. The vulnerability causes the restart of switches.
ModificadaMedia (6.5)1.1%—Huawei S5300ei FirmwareHuawei S5300si FirmwareHuawei S5310hi FirmwareHuawei S6300ei Firmware+914/4/201617/6/2026
Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V200R003SPH011 and V200R005C00 before V200R005SPH008; S2350EI and S5300LI Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH008, and V200R006C00…
ModificadaAlta (7.5)1.3%—Huawei S2350ei FirmwareHuawei S5300ei FirmwareHuawei S5300si FirmwareHuawei S5310hi Firmware+714/4/201617/6/2026
Memory leak in Huawei S5300EI, S5300SI, S5310HI, S6300EI/ S2350EI, and S5300LI Campus series switches with software V200R001C00 before V200R001SPH018, V200R002C00 before V200R003SPH011, and V200R003C00 before V200R003SPH011; S9300, S7700, and S9700 Campus series switches with software V200R001C00 before…
ModificadaAlta (7.8)1.5%—Huawei Campus Series Switch SoftwareHuawei Campus LSW S9700Huawei Campus S3300hiHuawei Campus S3700hi+917/6/201417/6/2026
Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700,…
ModificadaAlta (7.5)0.94%—Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+1420/6/201316/6/2026
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
ModificadaAlta (10)1.7%—Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+1420/6/201316/6/2026
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers…
ModificadaAlta (9.3)2.3%—Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+1420/6/201316/6/2026
Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI.
ModificadaMedia (6.5)3.5%—Huawei ACUHuawei AR 19/29/49Huawei AR G3Huawei ATN+6220/6/201316/6/2026
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500,…
ModificadaMedia (4.3)1.6%—IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+1422/6/201216/6/2026
Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.
ModificadaMedia (6.5)5.1%—IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+1422/6/201216/6/2026
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet…