Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
433 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.8% | — | Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+142 | 23/9/2021 | 17/6/2026 | A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory… | |
| Modificada | Alta (7.1) | 0.25% | — | Cisco Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file system. An attacker could exploit this vulnerability by placing a symbolic link in… | |
| Modificada | Media (6.5) | 0.97% | — | Cisco Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly restricted. An attacker could exploit this vulnerability by sending… | |
| Modificada | Media (5.5) | 0.23% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Vsmart Controller Firmware+8 | 23/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by running a CLI command that targets an arbitrary file on the… | |
| Modificada | Media (4.9) | 1.2% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.11, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security… | |
| Modificada | Media (6.2) | 0.33% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security… | |
| Modificada | Media (6.5) | 0.99% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.3, 8.6.0.9, 8.5.0.12, 8.3.0.16, 6.5.4.19, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address… | |
| Modificada | Alta (8.1) | 0.40% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that… | |
| Modificada | Alta (7.2) | 3.1% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS… | |
| Modificada | Alta (7.2) | 3.1% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS… | |
| Modificada | Alta (7.2) | 3.1% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS… | |
| Modificada | Alta (7.2) | 2.9% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 7/9/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS… | |
| Modificada | Alta (7.2) | 3.1% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this… | |
| Modificada | Alta (7.2) | 3.1% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this… | |
| Modificada | Crítica (9.8) | 2.4% | — | Arubanetworks Sd-wanArubanetworks ArubaosSiemens Scalance W1750d Firmware | 7/9/2021 | 17/6/2026 | A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security… | |
| Modificada | Alta (7.5) | 0.94% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 5/8/2021 | 17/6/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the… | |
| Modificada | Media (5.5) | 0.25% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 22/7/2021 | 17/6/2026 | A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists because access to sensitive information on an affected system is not sufficiently controlled. An… | |
| Modificada | Media (5.3) | 1.2% | — | Cisco Sd-wan | 22/7/2021 | 17/6/2026 | A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient handling of malformed MPLS packets that are processed by a… | |
| Modificada | Media (5.3) | 75% | — | Apache TomcatApache TomeeDebian LinuxOracle Agile Product Lifecycle Management+18 | 12/7/2021 | 25/8/2026 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if… | |
| Modificada | Media (6.5) | 0.42% | — | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller FirmwareCitrix Sd-wan Wanop | 16/6/2021 | 17/6/2026 | Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from… | |
| Modificada | Alta (7.8) | 0.25% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Vsmart ControllerCisco Vedge 100 Firmware+7 | 4/6/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system. This vulnerability exists because the affected software does not properly restrict access to privileged processes. An attacker could exploit this vulnerability by invoking… | |
| Modificada | Media (5.3) | 1.2% | — | Cisco Sd-wan Vmanage | 6/5/2021 | 17/6/2026 | A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the Cisco SD-WAN vManage Software must be in cluster mode. This vulnerability is due to the… | |
| Modificada | Media (4.3) | 0.37% | — | Cisco Sd-wan Vmanage | 6/5/2021 | 17/6/2026 | A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sensitive information. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage Software is running in multi-tenant mode. An attacker with access to a device that… | |
| Modificada | Alta (7.8) | 0.33% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Vsmart Controller Firmware+9 | 6/5/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An attacker could exploit… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Vsmart Controller FirmwareCisco Vedge 100 Firmware+8 | 6/5/2021 | 17/6/2026 | A vulnerability in the vDaemon process of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending… |