Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

9809 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.28%—HPE Arubaos-cx1/9/20264/9/2026
An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating…
AnalizadaMedia (6.5)0.56%—HPE Arubaos-cx1/9/20264/9/2026
An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files.
AnalizadaMedia (6.5)0.30%—HPE Arubaos-cx1/9/20264/9/2026
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
AnalizadaMedia (6.4)0.30%—HPE Arubaos-cx1/9/20264/9/2026
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and…
AnalizadaMedia (5.9)0.26%—HPE Arubaos-cx1/9/20264/9/2026
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
AnalizadaMedia (5.7)0.31%—HPE Arubaos-cx1/9/20264/9/2026
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.
AnalizadaMedia (5.3)0.34%—HPE Arubaos-cx1/9/20264/9/2026
Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.
AplazadaMedia (6.3)0.33%—PhpseclibAI1/9/20269/9/2026
phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and subtract(). During the Montgomery ladder in phpseclib/Crypt/EC/BaseCurves/Montgomery.php, the…
AplazadaBaja (3.7)0.46%—Filamentphp FilamentAI1/9/20269/9/2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating canAccessPanel(). For an account that canAccessPanel() denies, submitting the correct…
AnalizadaMedia (4.9)0.44%—HPE Arubaos-cx1/9/20265/10/2026
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
AnalizadaAlta (8.3)0.20%—HPE Arubaos-cx1/9/202622/9/2026
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of…
AnalizadaMedia (6.5)0.29%—HPE Arubaos-cx1/9/202622/9/2026
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
AnalizadaAlta (8.8)0.66%—HPE Arubaos-cx1/9/202622/9/2026
Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
AnalizadaAlta (8.8)0.47%—HPE Arubaos-cx1/9/202622/9/2026
An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
AnalizadaAlta (8.8)0.66%—HPE Arubaos-cx1/9/202622/9/2026
An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (8.8)0.80%—HPE Arubaos-cx1/9/202622/9/2026
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a…
AnalizadaCrítica (9.8)0.82%—HPE Arubaos-cx1/9/202622/9/2026
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with…
AplazadaMedia (6.5)0.45%—Filamentphp FilamentAI1/9/20269/9/2026
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-code cache key derived from both the app authentication secret and the submitted TOTP…
AplazadaBaja (3.5)0.29%—PhpmailerAIWallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled…
Pendiente de análisisAlta (7)0.14%—HP ImagediagsAI31/8/20263/9/2026
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaBaja (2.1)0.34%—Phpgurukul Student Information SystemAI29/8/202631/8/2026
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the…
AplazadaAlta (7.5)1.9%💥 ExploitPhpsysinfoAI28/8/20269/9/2026
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these…
AplazadaBaja (3.7)0.46%—Cakephp QueueAI27/8/20269/9/2026
CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can…
AnalizadaAlta (8.6)0.49%—Mongodb PHP DriverMongodb PHP Library27/8/202629/9/2026
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a…
AplazadaAlta (7.1)0.25%—WP W3allAIPhpbbAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.