Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.19% | — | Sodola-network Sl902-swtgw124as Firmware | 27/2/2026 | 17/6/2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakening session security. Attackers can exploit predictable session tokens combined with MD5's collision vulnerabilities to forge valid session cookies and gain unauthorized… | |
| Analizada | Media (6.9) | 0.47% | — | Sodola-network Sl902-swtgw124as Firmware | 27/2/2026 | 17/6/2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against the management interface. Attackers can conduct online password guessing attacks without account lockout or rate limiting restrictions to… | |
| Analizada | Alta (8.2) | 0.29% | — | Sodola-network Sl902-swtgw124as Firmware | 27/2/2026 | 17/6/2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administrative access to the… | |
| Analizada | Crítica (9.3) | 0.64% | — | Sodola-network Sl902-swtgw124as Firmware | 27/2/2026 | 17/6/2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to gain full… | |
| Analizada | Baja (2.3) | 0.19% | — | Refraction-networking Utls | 20/2/2026 | 17/6/2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cipher suite in the… | |
| Analizada | Media (6.5) | 0.38% | — | Refraction-networking Utls | 20/2/2026 | 17/6/2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a uTLS ClientHello spec. This allowed an… | |
| Analizada | Crítica (9.8) | 0.51% | — | Commscope Ruckus Network Director | 19/2/2026 | 17/6/2026 | In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the PostgreSQL database… | |
| Analizada | Crítica (9.8) | 0.50% | — | Commscope Ruckus Network Director | 19/2/2026 | 17/6/2026 | In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate remotely, gaining… | |
| Aplazada | Alta (7.8) | 0.15% | — | HPE Aruba Networking Clearpass OnguardAI | 18/2/2026 | 17/6/2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges. | |
| Aplazada | Media (5.5) | 0.44% | — | Sciyon Koyuan Thermoelectricity Heat Network Management SystemAI | 17/2/2026 | 17/6/2026 | A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the file /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx. The manipulation of the argument PGUID leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (6.5) | 0.32% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability. | |
| Analizada | Alta (8.8) | 0.30% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or… | |
| Aplazada | Media (4.6) | 0.35% | — | NetworksleuthAI | 11/2/2026 | 17/6/2026 | NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash. | |
| Aplazada | Media (6.6) | 0.55% | — | Paloaltonetworks Pan-osAI | 11/2/2026 | 17/6/2026 | A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW… | |
| Aplazada | Baja (1.3) | 0.19% | — | Paloaltonetworks Pan-osAIMicrosoft WindowsAI | 11/2/2026 | 17/6/2026 | An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so. | |
| Aplazada | Media (5.7) | 0.18% | — | Eaton Network M3AI | 9/2/2026 | 17/6/2026 | The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton Network M3 which is available on the Eaton download center. | |
| Analizada | Media (5.5) | 0.38% | — | Code-projects Social Networking Site | 7/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be… | |
| Analizada | Baja (2) | 20% | — | Dcnetworks Dcme-320 Firmware | 6/2/2026 | 17/6/2026 | A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a manipulation of the argument ip_list results in command injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Alta (8.4) | 0.38% | — | 10-strike Network Inventory ExplorerAI | 5/2/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code… | |
| Aplazada | Alta (8.4) | 0.71% | — | 10-strike Network Inventory ExplorerAI | 5/2/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution… | |
| Analizada | Media (6.1) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 4/2/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP… | |
| Aplazada | Baja (2.7) | 0.35% | — | Hillstone Networks Operation AND Maintenance Security GatewayAI | 4/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113. | |
| Aplazada | Alta (8.5) | 0.17% | — | Epson Easymessage Network ProjectionAI | 1/2/2026 | 17/6/2026 | EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that… |