Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
4192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7.2) | 0.23% | — | Paloaltonetworks Cortex XsiamPaloaltonetworks Cortex Xsoar | 13/4/2026 | 7/7/2026 | An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources. | |
| Analizada | Baja (2) | 0.18% | — | Paloaltonetworks Autonomous Digital Experience Manager | 13/4/2026 | 7/7/2026 | A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. | |
| Analizada | Media (4) | 0.15% | — | Paloaltonetworks Cortex XDR Agent | 13/4/2026 | 7/7/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. | |
| Analizada | Crítica (9.6) | 0.32% | — | HPE Aruba Networking Private 5G Core | 7/4/2026 | 17/6/2026 | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled… | |
| Analizada | Alta (7.5) | 0.20% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+146 | 6/4/2026 | 17/6/2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | |
| Analizada | Baja (2.7) | 0.31% | — | Ellanetworks Ella Core | 2/4/2026 | 24/7/2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an authenticated NetworkManager to modify any subscriber's policy while the audit… | |
| Analizada | Media (6.5) | 0.42% | — | Ellanetworks Ella Core | 2/4/2026 | 24/7/2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB to send NGAP handover failure messages to Ella Core can crash the process, causing service disruption for all connected subscribers. This… | |
| Analizada | Alta (8) | 0.27% | — | Cisco Evolved Programmable Network Manager | 1/4/2026 | 2/7/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API… | |
| Analizada | Media (4.3) | 0.34% | — | Networktocode Nautobot | 31/3/2026 | 24/7/2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be… | |
| Pendiente de análisis | Alta (8.3) | 0.98% | — | Catonetworks SocketAI | 31/3/2026 | 25/7/2026 | Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on the Socket’s internal system. | |
| Analizada | Media (6.9) | 0.22% | — | Networkactiv WEB Server | 30/3/2026 | 17/6/2026 | NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer… | |
| Pendiente de análisis | Alta (7.7) | 0.11% | — | UI Unifi Network ControllerAI | 27/3/2026 | 17/6/2026 | UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and… | |
| Pendiente de análisis | Crítica (9) | 0.08% | — | UI Unifi Network ControllerAIUI UAPAIUI UAP ACAIUI USWAI+1 | 27/3/2026 | 17/6/2026 | Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow… | |
| Analizada | Media (6.5) | 0.39% | — | Ellanetworks Ella Core | 27/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No… | |
| Analizada | Alta (7.2) | 0.56% | — | Ellanetworks Ella Core | 27/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager could replace the production database with a tampered copy to escalate to… | |
| Analizada | Media (6.5) | 0.26% | — | Ellanetworks Ella Core | 27/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 interface can cause Ella Core to hang, resulting in a denial of service for all… | |
| Analizada | Media (6.5) | 0.33% | — | Ellanetworks Ella Core | 27/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. Version 1.7.0 adds guards in… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Social Networking SiteAI | 27/3/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Aplazada | Baja (2) | 0.33% | — | Code-projects Social Networking SiteAI | 27/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly… | |
| Aplazada | Alta (8.8) | 0.36% | — | UI Unifi Network ServerAI | 24/3/2026 | 17/6/2026 | An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link. Affected Products: UniFi Network Server (Version 10.1.85 and earlier) Mitigation: Update UniFi Network Server to Version 10.1.89 or… | |
| Analizada | Alta (7.5) | 0.50% | — | Ellanetworks Ella Core | 24/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No… | |
| Analizada | Alta (7.5) | 0.54% | — | Ellanetworks Ella Core | 24/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInterestList` IE. An attacker able to send crafted NGAP messages to Ella Core can… | |
| Analizada | Alta (7.5) | 0.50% | — | Ellanetworks Ella Core | 24/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with invalid PDU Session IDs outside of 1-15. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication… | |
| Aplazada | Alta (7.7) | 0.55% | — | UI Unifi Network ApplicationAI | 19/3/2026 | 17/6/2026 | An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges. | |
| Aplazada | Crítica (10) | 28% | 💥 Exploit | UI Unifi Network ApplicationAI | 19/3/2026 | 17/6/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account. |