Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.3) | — | — | Arista Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role. | |
| Recibida | Crítica (9.8) | — | — | Arista Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system. | |
| Recibida | Alta (8.8) | — | — | Arista Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host. | |
| Recibida | Alta (8.8) | — | — | Arista Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system. | |
| Recibida | Alta (7.1) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the… | |
| Recibida | Alta (7.1) | — | — | Arista Wi-fi Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is… | |
| Recibida | Crítica (9) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access… | |
| Recibida | Alta (7.7) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode. | |
| Recibida | Baja (2.3) | — | — | Arista Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code… | |
| Recibida | Alta (8.7) | — | — | Arista Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless… | |
| Recibida | Crítica (9.4) | — | — | Arista Wi-fi Access PointsAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition… | |
| Recibida | Alta (8.6) | — | — | Arista Cloudvision CUEAI | 6/10/2026 | 6/10/2026 | An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service. | |
| Recibida | Media (6) | — | — | Arista Cloudvision CUEAI | 6/10/2026 | 6/10/2026 | An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data. | |
| Recibida | Alta (7.2) | — | — | Arista Cloudvision PortalAIArista Cloudvision SensorAI | 6/10/2026 | 6/10/2026 | On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. | |
| Recibida | Alta (7.6) | — | — | Arista CloudvisionAI | 6/10/2026 | 6/10/2026 | Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision. | |
| Aplazada | Media (5.4) | 0.14% | — | BacularisAI | 5/10/2026 | 6/10/2026 | In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload. | |
| Aplazada | Media (6.1) | 0.15% | — | BacularisAI | 5/10/2026 | 6/10/2026 | Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field. | |
| Aplazada | Alta (8.1) | 0.28% | — | Apache PolarisAI | 29/9/2026 | 1/10/2026 | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to… | |
| Analizada | Alta (7.3) | 0.10% | — | Claris Filemaker PRO | 23/9/2026 | 5/10/2026 | A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3. | |
| Analizada | Crítica (9.1) | 0.32% | — | Claris Filemaker Server | 23/9/2026 | 5/10/2026 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Crítica (9.1) | 0.29% | — | Claris Filemaker Server | 23/9/2026 | 5/10/2026 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Alta (7.8) | 0.13% | — | Claris Filemaker Server | 23/9/2026 | 6/10/2026 | A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Crítica (9.5) | 1.1% | ⚠ Explotación activa | Arista Velocloud Orchestrator | 22/9/2026 | 23/9/2026 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.… | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | Arista EOSAI | 16/9/2026 | 17/9/2026 | On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a… | |
| Pendiente de análisis | Media (6) | 0.32% | — | Arista EOSAI | 16/9/2026 | 17/9/2026 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users. |