Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

433 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+120/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.8)2.1%—Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section…
ModificadaAlta (8.8)2.1%—Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section…
ModificadaAlta (8.6)1.4%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+120/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.5)1.7%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+120/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.6)1.9%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+120/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.6)1.9%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+120/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.8)1.4%—Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section…
ModificadaAlta (7.8)1.3%—Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section…
ModificadaAlta (7.8)1.4%—Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section…
ModificadaAlta (7.8)1.4%—Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section…
ModificadaMedia (6.5)1.9%—Cisco Sd-wan Vmanage20/1/202117/6/2026
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker…
ModificadaAlta (8.1)7.8%—Fasterxml Jackson-databindNetapp Service Level ManagerDebian LinuxOracle Agile Product Lifecycle Management+2217/12/202025/8/2026
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
ModificadaAlta (7.2)1.6%—Arubanetworks ArubaosArubanetworks Sd-wan11/12/202017/6/2026
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attacker to load an untrusted or modified kernel in Aruba 9000 Gateway; Aruba 7000 Series Mobility…
ModificadaCrítica (9.8)2.1%—Arubanetworks ArubaosArubanetworks Sd-wan11/12/202017/6/2026
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s):…
ModificadaCrítica (9.8)5.1%—Arubanetworks ArubaosArubanetworks Sd-wan11/12/202017/6/2026
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers;…
ModificadaAlta (7.5)25%💥 PoCApache TomcatNetapp Element Plug-inNetapp Oncommand System ManagerDebian Linux+83/12/202017/6/2026
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead…
ModificadaAlta (7.5)17%—Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Oncommand Workflow AutomationNetapp Service Level Manager+353/12/202025/8/2026
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
ModificadaMedia (6.5)1.2%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WAN Orchestrator user may inject code into SQL queries which may lead to information disclosure.
ModificadaAlta (7.2)1.6%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privileges may be able to execute arbitrary code on the underlying operating system.
ModificadaCrítica (9.8)2.9%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.
ModificadaAlta (8.8)43%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal. An authenticated SD-WAN Orchestrator user is able to traversal directories which may lead to code execution of files.
ModificadaAlta (8.8)1.4%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization levels leading to a privilege escalation issue. An authenticated SD-WAN Orchestrator user may exploit an application weakness and call a vulnerable API to elevate their privileges.
ModificadaMedia (6.5)22%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to unauthorized data access.
ModificadaAlta (8.8)2.4%—Citrix Sd-wan16/11/202017/6/2026
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
Orbitaley — Vulnerabilidades