Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1845 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)1.4%—Arubanetworks Arubaos13/1/202617/6/2026
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
AnalizadaAlta (7.2)1.3%—Arubanetworks Arubaos13/1/202617/6/2026
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)0.55%—Arubanetworks Arubaos13/1/202617/6/2026
A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.
AnalizadaCrítica (9.1)0.44%—Arubanetworks Arubaos13/1/202617/6/2026
Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in…
AnalizadaAlta (8.5)0.11%—Versa-networks Sase Client20/12/20257/10/2026
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user.…
ModificadaAlta (7.2)0.40%—Nozominetworks CMCNozominetworks Guardian18/12/202517/6/2026
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device…
ModificadaMedia (5.3)0.20%—Nozominetworks CMCNozominetworks Guardian18/12/202517/6/2026
A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and…
ModificadaAlta (7.1)0.26%—Nozominetworks CMCNozominetworks Guardian18/12/202517/6/2026
A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a malicious report…
ModificadaBaja (2.3)0.18%—Nozominetworks CMCNozominetworks Guardian18/12/202530/9/2026
A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots.…
AplazadaAlta (8.6)1.4%—Ruijienetworks RG Ap180AI18/12/20257/10/2026
RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.
AnalizadaCrítica (9.2)0.31%—Ruijienetworks Reyee OS15/12/202517/6/2026
ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the…
AnalizadaAlta (8.8)2.8%—Ruijienetworks Reyee OSRuijie Rg-rap2200(e) Firmware11/12/202517/6/2026
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.
AnalizadaCrítica (9.8)3.4%⚠ Explotación activaArraynetworks Arrayos AG5/12/202517/6/2026
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
AplazadaBaja (2.7)0.22%—Splunk Add-on FOR Palo Alto NetworksAI26/11/202517/6/2026
In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new “Data Security Accounts“. The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default…
AnalizadaCrítica (9.8)0.53%—Dasannetworks Ds2924 Firmware19/11/202517/6/2026
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
AnalizadaAlta (8.8)0.89%—Arubanetworks Arubaos18/11/202517/6/2026
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (7.5)0.39%—Arubanetworks Arubaos18/11/202517/6/2026
A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
AnalizadaAlta (7.2)0.99%—Arubanetworks Airwave18/11/202517/6/2026
A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system.
AplazadaMedia (4.4)0.09%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaBaja (1.1)0.13%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaBaja (1.1)0.11%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.
AplazadaMedia (6.6)0.56%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-seriesAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Prisma AccessAI13/11/202517/6/2026
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the…
AplazadaAlta (8.6)0.60%—Ruijienetworks Rg-est300AI16/10/202517/6/2026
Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. Anyone with the knowledge of the related credentials can log in to the affected device, leading to information disclosure, altering the system…
AnalizadaMedia (4.9)0.45%—Arubanetworks Arubaos14/10/202517/6/2026
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
AnalizadaMedia (4.9)0.45%—Arubanetworks Arubaos14/10/202517/6/2026
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.