Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.32% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. | |
| Aplazada | Alta (7.2) | 0.14% | — | HPE Aruba Networking EdgeconnectAIHPE Aruba Networking Edgeconnect Sd-wanAI | 16/9/2025 | 17/6/2026 | A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized… | |
| Aplazada | Alta (7.2) | 0.64% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying… | |
| Aplazada | Alta (7.5) | 0.36% | — | HPE Aruba Networking Edgeconnect OSAI | 16/9/2025 | 17/6/2026 | A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly | |
| Aplazada | Alta (8.8) | 0.47% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying… | |
| Analizada | Media (4.7) | 0.37% | — | Microsoft Edge | 16/9/2025 | 17/6/2026 | Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (4.7) | 0.39% | — | Microsoft Edge Chromium | 5/9/2025 | 17/6/2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | |
| Aplazada | Alta (8.4) | 0.92% | — | Progress OpenedgeAI | 4/9/2025 | 17/6/2026 | It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process. An RMI interface permitted manipulation of a configuration property with inadequate… | |
| Aplazada | Alta (7.5) | 0.67% | — | UI Edgemax EdgeswitchAI | 21/8/2025 | 17/6/2026 | An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent network. Affected Products: EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) Mitigation: Update the EdgeMAX EdgeSwitch to Version 1.11.1 or later. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Edge Application Manager | 20/8/2025 | 17/6/2026 | IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Media (4.4) | 0.11% | — | IBM Edge Application Manager | 20/8/2025 | 17/6/2026 | IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authorization to access due to incorrect permission assignment. | |
| Aplazada | Alta (8.1) | 0.67% | — | Edge-themes Edge CPTAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT edge-cpt allows PHP Local File Inclusion.This issue affects Edge CPT: from n/a through <= 1.4. | |
| Analizada | Media (5.5) | 0.14% | — | Dell Poweredge R7425 FirmwareDell Poweredge R7415 FirmwareDell Poweredge R6415 Firmware | 14/8/2025 | 17/6/2026 | Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.9) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+22 | 13/8/2025 | 17/6/2026 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/8/2025 | 17/6/2026 | When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Analizada | Media (4.3) | 0.49% | — | Microsoft Edge | 12/8/2025 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (4.3) | 0.52% | — | Microsoft Edge | 12/8/2025 | 17/6/2026 | The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Baja (1.8) | 0.14% | — | Intel Edger8r ToolAIIntel SGX SDKAI | 12/8/2025 | 17/6/2026 | Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Baja (2.1) | 0.18% | — | Intel Tiber Edge PlatformAI | 12/8/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Baja (2.1) | 0.14% | — | Intel Tiber Edge PlatformAIIntel Edge OrchestratorAI | 12/8/2025 | 17/6/2026 | Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.1) | 0.21% | — | Intel Tiber Edge PlatformAI | 12/8/2025 | 17/6/2026 | Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Aplazada | Media (5.1) | 0.21% | — | Intel Tiber Edge PlatformAIIntel Edge OrchestratorAI | 12/8/2025 | 17/6/2026 | Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (5.9) | 0.23% | — | Intel Tiber Edge PlatformAIIntel Edge OrchestratorAI | 12/8/2025 | 17/6/2026 | Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (6.9) | 0.20% | — | Intel Tiber Edge PlatformAI | 12/8/2025 | 17/6/2026 | Improper neutralization for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | |
| Aplazada | Baja (2.3) | 0.16% | — | Intel Tiber Edge PlatformAIIntel Edge OrchestratorAI | 12/8/2025 | 17/6/2026 | Improper access control for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. |