Vulnerabilities

Summary — last 7 days

New vulnerabilities3,241▲ 698 vs. last week
Critical / high1,519▲ 132 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)235▲ 221 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.9)0.57%—Huawei Oceanstor 5800 V3 FirmwareHuawei Oceanstor 6900 V3 Firmware11/22/20176/17/2026
OceanStor 5800 V3 with software V300R002C00 and V300R002C10, OceanStor 6900 V3 V300R001C00 has an information leakage vulnerability. Products use TLS1.0 to encrypt. Attackers can exploit TLS1.0's vulnerabilities to decrypt data to obtain sensitive information.
ModifiedMedium (6.5)0.62%—Huawei Oceanstor 5800 V3 Firmware4/2/20176/17/2026
The Huawei OceanStor 5800 V300R003C00 has an integer overflow vulnerability. An authenticated attacker may send massive abnormal Network File System (NFS) packets, causing an anomaly in specific disk arrays.
ModifiedHigh (7.5)2.5%—Huawei Oceanstor 5800 V31/27/20176/17/2026
Huawei Oceanstor 5800 before V300R002C10SPC100 allows remote attackers to cause a denial of service (CPU consumption) via a large number of crafted HTTP packets.
AnalyzedHigh (8.1)96%⚠ Active exploitation💥 ExploitHuawei Agile Controller-campus FirmwareHuawei AnyofficeHuawei LogcenterHuawei Firehunter6000 Firmware+164/26/201610/9/2026
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.