Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Media (4.6) | 0.35% | — | NetworksleuthAI | 11/2/2026 | 17/6/2026 | NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash. | |
| Aplazada | Media (6.6) | 0.55% | — | Paloaltonetworks Pan-osAI | 11/2/2026 | 17/6/2026 | A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW… | |
| Aplazada | Baja (1.3) | 0.19% | — | Paloaltonetworks Pan-osAIMicrosoft WindowsAI | 11/2/2026 | 17/6/2026 | An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so. | |
| Analizada | Baja (2) | 20% | — | Dcnetworks Dcme-320 Firmware | 6/2/2026 | 17/6/2026 | A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a manipulation of the argument ip_list results in command injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.7) | 0.35% | — | Hillstone Networks Operation AND Maintenance Security GatewayAI | 4/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113. | |
| Aplazada | Alta (7.1) | 0.71% | — | Ruijienetworks Switch Eweb S29 RgosAI | 29/1/2026 | 17/6/2026 | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration… | |
| Aplazada | Crítica (9.3) | 1.6% | — | Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance Managed RoutersAI | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: This issue affects Session Smart Conductor: This issue… | |
| Aplazada | Alta (7.8) | 0.29% | — | Solidworks EdrawingsAI | 26/1/2026 | 17/6/2026 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Alta (7.8) | 0.29% | — | Solidworks EdrawingsAI | 26/1/2026 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Alta (7.1) | 0.27% | — | Purethemes Workscout-coreAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affects WorkScout-Core: from n/a through <= 1.7.06. | |
| Aplazada | Alta (7.1) | 0.27% | — | Purethemes WorkscoutAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout workscout allows Reflected XSS.This issue affects WorkScout: from n/a through <= 4.1.07. | |
| Aplazada | Media (5.8) | 0.23% | — | Fullworksplugins Quick Contact FormAI | 17/1/2026 | 17/6/2026 | The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_validate_form' AJAX endpoint allowing a user controlled parameter to set the 'from' email address. This makes it possible for unauthenticated attackers to send emails to… | |
| Analizada | Media (6.6) | 0.75% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 15/1/2026 | 17/6/2026 | A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. | |
| Analizada | Media (4.8) | 0.27% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Crítica (9.8) | 0.66% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity… | |
| Analizada | Alta (7.2) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data… | |
| Analizada | Alta (7.2) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data… | |
| Analizada | Alta (7.2) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 14/1/2026 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data… | |
| Analizada | Media (5.3) | 0.36% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the… | |
| Analizada | Alta (7.5) | 0.38% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the… | |
| Analizada | Media (6.5) | 0.36% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system. | |
| Analizada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted… | |
| Analizada | Alta (7.2) | 0.50% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying… |