Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.99% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to improperly access and modify devices and management user details. A… | |
| Modificada | Alta (7.2) | 3.0% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to… | |
| Modificada | Alta (7.2) | 3.2% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to… | |
| Modificada | Alta (8.8) | 0.63% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system.… | |
| Modificada | Alta (8.8) | 0.63% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system.… | |
| Modificada | Alta (8.8) | 13% | — | Carrierwave Project Carrierwave | 8/2/2021 | 17/6/2026 | CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing… | |
| Modificada | Media (4.3) | 1.2% | — | Carrierwave Project Carrierwave | 8/2/2021 | 17/6/2026 | CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather… | |
| Modificada | Alta (7.5) | 1.5% | — | Arubanetworks Airwave Glass | 15/1/2021 | 17/6/2026 | In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately gain administrative access on the web… | |
| Modificada | Crítica (9.8) | 2.9% | — | Arubanetworks Airwave Glass | 15/1/2021 | 17/6/2026 | There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system. | |
| Modificada | Crítica (9.8) | 7.2% | — | Arubanetworks Airwave Glass | 15/1/2021 | 17/6/2026 | There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system. | |
| Modificada | Alta (7.2) | 3.2% | — | Arubanetworks Airwave Glass | 15/1/2021 | 17/6/2026 | Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system. | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon OCE Colorwave 3500 Firmware | 16/11/2020 | 17/6/2026 | The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI. | |
| Modificada | Alta (7.2) | 2.7% | — | Arubanetworks Airwave Glass | 4/11/2020 | 17/6/2026 | A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Crítica (9.8) | 2.2% | — | Arubanetworks Airwave Glass | 4/11/2020 | 17/6/2026 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Crítica (9.8) | 1.8% | — | Arubanetworks Airwave Glass | 26/10/2020 | 17/6/2026 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Media (5.8) | 0.83% | — | Arubanetworks Airwave Glass | 26/10/2020 | 17/6/2026 | A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Alta (8.8) | 1.4% | — | Arubanetworks Airwave Glass | 26/10/2020 | 17/6/2026 | A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Crítica (9.8) | 1.4% | — | Arubanetworks Airwave Glass | 26/10/2020 | 17/6/2026 | A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Alta (7.2) | 2.7% | — | Arubanetworks Airwave Glass | 26/10/2020 | 17/6/2026 | A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Alta (7.2) | 2.7% | — | Arubanetworks Airwave Glass | 26/10/2020 | 17/6/2026 | A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | |
| Modificada | Crítica (9.8) | 3.0% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+25 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service. | |
| Modificada | Alta (7.2) | 23% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+24 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple… | |
| Modificada | Crítica (9.8) | 3.3% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+22 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts. | |
| Modificada | Alta (7.5) | 3.5% | — | Canon OCE Colorwave 500 Firmware | 19/3/2020 | 17/6/2026 | The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version. | |
| Modificada | Alta (8.8) | 0.70% | — | Canon OCE Colorwave 500 Firmware | 19/3/2020 | 17/6/2026 | The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version. |