Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 359 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 0.71% | — | Huawei S12700 FirmwareHuawei S1700 FirmwareHuawei S2700 FirmwareHuawei S3700 Firmware+4 | 5/3/2018 | 17/6/2026 | Huawei S12700 V200R005C00; V200R006C00; V200R007C00; V200R007C01; V200R007C20; V200R008C00; V200R009C00;S1700 V200R006C10; V200R009C00;S2700 V100R006C03; V200R003C00; V200R005C00; V200R006C00; V200R006C10; V200R007C00; V200R007C00B050; V200R007C00SPC009T; V200R007C00SPC019T; V200R008C00; V200R009C00;S3700… | |
| Modificada | Media (5.9) | 1.7% | — | Huawei S9300 FirmwareHuawei S9300e FirmwareHuawei S7700 FirmwareHuawei S9700 Firmware+8 | 8/1/2018 | 17/6/2026 | Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal. | |
| Modificada | Alta (7.5) | 0.94% | — | Huawei S2300 FirmwareHuawei S2700 FirmwareHuawei S3300 FirmwareHuawei S3700 Firmware+18 | 8/6/2017 | 17/6/2026 | The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message. | |
| Modificada | Alta (7.5) | 0.74% | — | Huawei Campus S3700hi FirmwareHuawei S5700 FirmwareHuawei S6700 FirmwareHuawei S3300hi Firmware+10 | 2/4/2017 | 17/6/2026 | Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S2350 with software V200R003C00SPC300; S2750 with software… | |
| Modificada | Baja (3.7) | 74% | — | Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+57 | 1/4/2015 | 17/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally… | |
| Modificada | Alta (7.8) | 1.5% | — | Huawei Campus Series Switch SoftwareHuawei Campus LSW S9700Huawei Campus S3300hiHuawei Campus S3700hi+9 | 17/6/2014 | 17/6/2026 | Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700,… | |
| Modificada | Alta (7.5) | 0.94% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack. | |
| Modificada | Alta (10) | 1.7% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers… | |
| Modificada | Alta (9.3) | 2.3% | — | Huawei AR 18-1xHuawei AR 18-2xHuawei AR 18-3xHuawei AR 19/29/49+14 | 20/6/2013 | 16/6/2026 | Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI. | |
| Modificada | Media (6.5) | 3.5% | — | Huawei ACUHuawei AR 19/29/49Huawei AR G3Huawei ATN+62 | 20/6/2013 | 16/6/2026 | The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500,… | |
| Modificada | Media (4.3) | 1.6% | — | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter. | |
| Modificada | Media (6.5) | 5.1% | — | IBM DS Storage Manager Host SoftwareIBM Ds4100IBM Ds4200IBM Ds4300+14 | 22/6/2012 | 16/6/2026 | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet… |