Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4193 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.61% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input… | |
| Analizada | Alta (7.5) | 0.53% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying… | |
| Analizada | Alta (7.5) | 0.40% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation could cause the… | |
| Analizada | Alta (7.5) | 0.33% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical… | |
| Analizada | Alta (7.5) | 0.33% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical… | |
| Analizada | Alta (7.2) | 0.96% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points… | |
| Analizada | Media (5.3) | 0.26% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note:… | |
| Analizada | Alta (7.2) | 0.56% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 0.27% | — | Arubanetworks Arubaos | 12/5/2026 | 11/8/2026 | A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and… | |
| Aplazada | Alta (8.2) | 0.41% | — | Juno Network JunoclawnAIJuno Network Wavs BridgeAI | 12/5/2026 | 17/6/2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, resulting in an SSRF vulnerability. This vulnerability is fixed in 0.x.y-security-1. | |
| Aplazada | Crítica (9.8) | 0.37% | — | Juno Network JunoclawwAI | 12/5/2026 | 17/6/2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accepted 'mnemonic: string' as an explicit tool-call parameter. The BIP-39 seed was consequently embedded in the LLM tool-call… | |
| Aplazada | Alta (8.4) | 0.26% | — | Juno Network JunoclawlAIJuno Network Plugin ShellAI | 12/5/2026 | 17/6/2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check could be bypassed by adversarial argument constructions, allowing unauthorized command execution on the host when combined with the companion advisory. Pre-patch, the… | |
| Aplazada | Alta (8.4) | 0.22% | — | Juno Network JunoclawfastaioAIJuno Network Plugin ShellAI | 12/5/2026 | 17/6/2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument string to the shell's parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command… | |
| Aplazada | Alta (8.7) | 0.54% | — | Network-aiAI | 11/5/2026 | 17/6/2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no authentication, session, origin, or token check, and dispatches them directly to the orchestrator's tool registry. The default bind address is 0.0.0.0. As a result, any party… | |
| Analizada | Media (5.3) | 0.41% | — | Zfnd Zebra-chainZfnd Zebra-networkZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus… | |
| Analizada | Crítica (9.3) | 32% | ⚠ Explotación activa💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 6/5/2026 | 17/6/2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this… | |
| Pendiente de análisis | Ninguna (0) | 0.31% | — | Cisco Crosswork Network ControllerAICisco Network Services OrchestratorAI | 6/5/2026 | 17/6/2026 | Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis,… | |
| Analizada | Media (6.4) | 0.21% | 💥 PoC | Cisco IOT Field Network Director | 6/5/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could… | |
| Analizada | Media (6.5) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this… | |
| Analizada | Alta (7.7) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (7.5) | 0.18% | — | Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+253 | 4/5/2026 | 7/10/2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |
| Analizada | Alta (7.5) | 0.18% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 7/10/2026 | Transient DOS when processing target power rate tables during channel configuration. | |
| Aplazada | Media (6.8) | 0.13% | — | Infiltrator Network Security ScannerAI | 26/4/2026 | 17/6/2026 | Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a 6000-byte payload into the Scan Target field and trigger a denial of service condition when the Scan button is clicked. | |
| Aplazada | Alta (8.2) | 0.66% | — | Ossn Open Source Social NetworkAI | 24/4/2026 | 17/6/2026 | Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file size on disk may be… |