Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2624 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.8)——Backstage Plugin-auth-backend-module-cloudflare-access-providerAI6/10/20266/10/2026
Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature…
RecibidaAlta (7.1)——Arista WI FI Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the…
RecibidaAlta (7.1)——Arista Wi-fi Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is…
RecibidaCrítica (9)——Arista WI FI Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access…
RecibidaAlta (7.7)——Arista WI FI Access PointAI6/10/20266/10/2026
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.
RecibidaBaja (2.3)——Arista Access PointAI6/10/20266/10/2026
On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code…
RecibidaAlta (8.7)——Arista Access PointAI6/10/20266/10/2026
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless…
RecibidaCrítica (9.4)——Arista Wi-fi Access PointsAI6/10/20266/10/2026
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition…
En análisisCrítica (9.3)0.13%—Watchguard Kernel Memory Access DriverAI1/10/20262/10/2026
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process…
Pendiente de análisisCrítica (9.8)0.44%—Fortra Core Privileged Access ManagerAI1/10/20261/10/2026
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
AplazadaMedia (4.3)0.21%—Prevent Files Folders AccessAI30/9/202630/9/2026
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
AplazadaAlta (8.2)0.25%—Wpdataaccess WP Data AccessAI30/9/202630/9/2026
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
Pendiente de análisisAlta (7.2)0.55%—HPE Networking Instant ON Access PointAI29/9/20266/10/2026
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating…
AplazadaCrítica (9.3)0.27%—Watchguard Access PointAI28/9/202628/9/2026
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
AnalizadaCrítica (9.3)2.2%⚠ Explotación activaF5 Big-ip Access Policy Manager22/9/202623/9/2026
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource…
Pendiente de análisisMedia (4.4)0.20%—Zscaler Internet AccessAI18/9/202618/9/2026
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
Pendiente de análisisAlta (8.8)0.69%—Solarwinds Access Rights ManagerAI17/9/202618/9/2026
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Pendiente de análisisMedia (6.8)0.47%—Zope AccesscontrolAI16/9/202630/9/2026
Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are reached through a str subclass. In both ImplPython.py and…
AnalizadaBaja (3.1)0.29%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful…
AnalizadaAlta (8.5)0.33%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.…
AnalizadaCrítica (9.1)0.49%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While…
AnalizadaCrítica (9.6)0.36%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Access Manager. While…
AnalizadaAlta (8.1)0.39%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.…
AnalizadaCrítica (9.8)0.51%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.…