Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.8) | — | — | Backstage Plugin-auth-backend-module-cloudflare-access-providerAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature… | |
| Recibida | Alta (7.1) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the… | |
| Recibida | Alta (7.1) | — | — | Arista Wi-fi Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is… | |
| Recibida | Crítica (9) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access… | |
| Recibida | Alta (7.7) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode. | |
| Recibida | Baja (2.3) | — | — | Arista Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code… | |
| Recibida | Alta (8.7) | — | — | Arista Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless… | |
| Recibida | Crítica (9.4) | — | — | Arista Wi-fi Access PointsAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition… | |
| En análisis | Crítica (9.3) | 0.13% | — | Watchguard Kernel Memory Access DriverAI | 1/10/2026 | 2/10/2026 | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process… | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Fortra Core Privileged Access ManagerAI | 1/10/2026 | 1/10/2026 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | |
| Aplazada | Media (4.3) | 0.21% | — | Prevent Files Folders AccessAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | |
| Aplazada | Alta (8.2) | 0.25% | — | Wpdataaccess WP Data AccessAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | |
| Pendiente de análisis | Alta (7.2) | 0.55% | — | HPE Networking Instant ON Access PointAI | 29/9/2026 | 6/10/2026 | A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Watchguard Access PointAI | 28/9/2026 | 28/9/2026 | An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session. | |
| Analizada | Crítica (9.3) | 2.2% | ⚠ Explotación activa | F5 Big-ip Access Policy Manager | 22/9/2026 | 23/9/2026 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource… | |
| Pendiente de análisis | Media (4.4) | 0.20% | — | Zscaler Internet AccessAI | 18/9/2026 | 18/9/2026 | A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances. | |
| Pendiente de análisis | Alta (8.8) | 0.69% | — | Solarwinds Access Rights ManagerAI | 17/9/2026 | 18/9/2026 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Pendiente de análisis | Media (6.8) | 0.47% | — | Zope AccesscontrolAI | 16/9/2026 | 30/9/2026 | Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are reached through a str subclass. In both ImplPython.py and… | |
| Analizada | Baja (3.1) | 0.29% | — | Oracle Access Manager | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Access Manager | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Access Manager | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Access Manager | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Access Manager. While… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Access Manager | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Access Manager | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… |