Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

525 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.99%—Arubanetworks Airwave5/3/202117/6/2026
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to improperly access and modify devices and management user details. A…
ModificadaAlta (7.2)3.0%—Arubanetworks Airwave5/3/202117/6/2026
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to…
ModificadaAlta (7.2)3.2%—Arubanetworks Airwave5/3/202117/6/2026
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to…
ModificadaAlta (8.8)0.63%—Arubanetworks Airwave5/3/202117/6/2026
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system.…
ModificadaAlta (8.8)0.63%—Arubanetworks Airwave5/3/202117/6/2026
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system.…
ModificadaAlta (8.8)13%—Carrierwave Project Carrierwave8/2/202117/6/2026
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing…
ModificadaMedia (4.3)1.2%—Carrierwave Project Carrierwave8/2/202117/6/2026
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather…
ModificadaAlta (7.5)1.5%—Arubanetworks Airwave Glass15/1/202117/6/2026
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately gain administrative access on the web…
ModificadaCrítica (9.8)2.9%—Arubanetworks Airwave Glass15/1/202117/6/2026
There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system.
ModificadaCrítica (9.8)7.2%—Arubanetworks Airwave Glass15/1/202117/6/2026
There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system.
ModificadaAlta (7.2)3.2%—Arubanetworks Airwave Glass15/1/202117/6/2026
Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system.
ModificadaCrítica (9.8)1.1%—Canon OCE Colorwave 3500 Firmware16/11/202017/6/2026
The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.
ModificadaAlta (7.2)2.7%—Arubanetworks Airwave Glass4/11/202017/6/2026
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaCrítica (9.8)2.2%—Arubanetworks Airwave Glass4/11/202017/6/2026
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaCrítica (9.8)1.8%—Arubanetworks Airwave Glass26/10/202017/6/2026
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaMedia (5.8)0.83%—Arubanetworks Airwave Glass26/10/202017/6/2026
A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaAlta (8.8)1.4%—Arubanetworks Airwave Glass26/10/202017/6/2026
A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaCrítica (9.8)1.4%—Arubanetworks Airwave Glass26/10/202017/6/2026
A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaAlta (7.2)2.7%—Arubanetworks Airwave Glass26/10/202017/6/2026
A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaAlta (7.2)2.7%—Arubanetworks Airwave Glass26/10/202017/6/2026
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
ModificadaCrítica (9.8)3.0%—Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+2515/10/202017/6/2026
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.
ModificadaAlta (7.2)23%—Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+2415/10/202017/6/2026
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple…
ModificadaCrítica (9.8)3.3%—Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+2215/10/202017/6/2026
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.
ModificadaAlta (7.5)3.5%—Canon OCE Colorwave 500 Firmware19/3/202017/6/2026
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version.
ModificadaAlta (8.8)0.70%—Canon OCE Colorwave 500 Firmware19/3/202017/6/2026
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.
Orbitaley — Vulnerabilidades