Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1845 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… | |
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… | |
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 1.6% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user. | |
| Analizada | Alta (7.2) | 1.6% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user. | |
| Modificada | Alta (7.2) | 0.61% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input… | |
| Analizada | Alta (7.5) | 0.53% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying… | |
| Analizada | Alta (7.5) | 0.40% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation could cause the… | |
| Analizada | Alta (7.5) | 0.33% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical… | |
| Analizada | Alta (7.5) | 0.33% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical… | |
| Analizada | Alta (7.2) | 0.96% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points… | |
| Analizada | Media (5.3) | 0.26% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note:… | |
| Analizada | Alta (7.2) | 0.56% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 0.27% | — | Arubanetworks Arubaos | 12/5/2026 | 11/8/2026 | A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and… | |
| Analizada | Crítica (9.3) | 32% | ⚠ Explotación activa💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 6/5/2026 | 17/6/2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this… | |
| En análisis | Alta (7.2) | 0.23% | — | Paloaltonetworks Cortex XsiamPaloaltonetworks Cortex Xsoar | 13/4/2026 | 7/7/2026 | An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources. | |
| Analizada | Baja (2) | 0.18% | — | Paloaltonetworks Autonomous Digital Experience Manager | 13/4/2026 | 7/7/2026 | A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. | |
| Analizada | Media (4) | 0.15% | — | Paloaltonetworks Cortex XDR Agent | 13/4/2026 | 7/7/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. | |
| Analizada | Baja (2.7) | 0.31% | — | Ellanetworks Ella Core | 2/4/2026 | 24/7/2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an authenticated NetworkManager to modify any subscriber's policy while the audit… |