VYPR

Vendor CVEs

Broadcom Corporation

All CVEs

798 total · sorted by risk
  • CVE-2021-40438CriKEVSep 16, 2021
    risk 0.85cvss 9.0epss 1.00

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

  • CVE-2018-1273CriKEVApr 11, 2018
    risk 0.82cvss 9.8epss 0.96

    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially…

  • CVE-2020-8012CriFeb 18, 2020
    risk 0.73cvss 9.8epss 0.77

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

  • CVE-2014-0160HigKEVApr 7, 2014
    risk 0.72cvss 7.5epss 1.00

    The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by…

  • CVE-2025-22225HigKEVMar 4, 2025
    risk 0.71cvss 8.2epss 0.01

    VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

  • CVE-2020-8010CriFeb 18, 2020
    risk 0.71cvss 9.8epss 0.49

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

  • CVE-2017-9417CriJun 4, 2017
    risk 0.71cvss 9.8epss 0.48

    Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

  • CVE-2017-0561CriApr 7, 2017
    risk 0.69cvss 9.8epss 0.30

    A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of the Wi-Fi SoC.…

  • CVE-2018-15691CriAug 30, 2018
    risk 0.68cvss 9.8epss 0.17

    Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

  • CVE-2018-9022CriJun 18, 2018
    risk 0.68cvss 9.8epss 0.20

    An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.

  • CVE-2018-9021CriJun 18, 2018
    risk 0.68cvss 9.8epss 0.19

    An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.

  • CVE-2015-4664CriJun 18, 2018
    risk 0.68cvss 9.8epss 0.21

    An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.

  • CVE-2013-4659CriMar 14, 2017
    risk 0.68cvss 9.8epss 0.14

    Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.

  • CVE-2017-11120CriSep 28, 2017
    risk 0.67cvss 9.8epss 0.09

    On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.

  • CVE-2026-22719HigKEVFeb 25, 2026
    risk 0.66cvss 8.1epss 0.17

    VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  …

  • CVE-2024-23616CriJan 26, 2024
    risk 0.65cvss 10.0epss 0.02

    A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

  • CVE-2024-23615CriJan 26, 2024
    risk 0.65cvss 10.0epss 0.02

    A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.

  • CVE-2024-23614CriJan 26, 2024
    risk 0.65cvss 10.0epss 0.02

    A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.

  • CVE-2024-23613CriJan 26, 2024
    risk 0.65cvss 10.0epss 0.02

    A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

  • CVE-2016-8205CriJan 14, 2017
    risk 0.65cvss 9.8epss 0.13

    A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.

  • CVE-2026-59310CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

  • CVE-2025-69270CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

  • CVE-2025-69269CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier.

  • CVE-2025-8660CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.00

    Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.

  • CVE-2024-4282CriFeb 15, 2025
    risk 0.64cvss 9.8epss 0.00

    Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.

  • CVE-2024-37085MedKEVJun 25, 2024
    risk 0.64cvss 6.8epss 0.26

    VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vs…

  • CVE-2023-4344CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

  • CVE-2023-4342CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

  • CVE-2023-4341CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

  • CVE-2023-4340CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file

  • CVE-2023-4338CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

  • CVE-2023-4337CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation

  • CVE-2023-4336CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

  • CVE-2023-4329CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute

  • CVE-2023-4325CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

  • CVE-2023-4324CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

  • CVE-2023-4323CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

  • CVE-2023-23952CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.

  • CVE-2022-33186CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying…

  • CVE-2022-37016CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2022-37015CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are…

  • CVE-2022-33754CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

  • CVE-2022-33752CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

  • CVE-2022-33750CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.

  • CVE-2022-28163CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.

  • CVE-2021-27797CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.

  • CVE-2022-23992CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges.

  • CVE-2021-42774CriNov 12, 2021
    risk 0.64cvss 9.8epss 0.02

    Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform…

  • CVE-2021-42772CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.01

    Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote GetDumpFile command that could allow a user to attempt various attacks. In…

  • CVE-2021-30648CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.01

    The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the…

Page 1 of 16