Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1845 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.48%—Paloaltonetworks Expedition11/1/202517/6/2026
A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.
AnalizadaMedia (6.9)13%—Paloaltonetworks Expedition11/1/202517/6/2026
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.
AnalizadaAlta (7)0.36%—Paloaltonetworks Expedition11/1/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition…
AnalizadaCrítica (9.2)0.62%—Paloaltonetworks Expedition11/1/202517/6/2026
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
AplazadaMedia (6.9)0.44%—Txone Networks Portable InspectorAITxone Networks Portable Inspector PRO EditionAI8/1/202517/6/2026
Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspector Pro Edition allows remote attacker to crash management service. The Denial of Service situation can be resolved by restarting the management service. This issue affects Portable Inspector: through…
AplazadaAlta (7.1)0.26%—Lemonadestudio Lemonade Social Networks Autoposter PinterestAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0.
AnalizadaAlta (8.7)29%⚠ Explotación activaPaloaltonetworks Pan-osPaloaltonetworks Prisma Access27/12/202417/6/2026
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance…
AplazadaAlta (8.6)0.64%—Hms-networks Ewon Flexy 205AI19/12/202417/6/2026
A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633).
AplazadaMedia (5.9)0.20%—Teltonika-networks RutosAITeltonika-networks TswosAI10/12/202417/6/2026
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API.
AnalizadaCrítica (9.2)0.69%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.
AnalizadaCrítica (9.3)0.60%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.
AnalizadaAlta (8.7)0.39%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, and receive partial messages being sent to and from devices.
AnalizadaAlta (7.1)0.28%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and sniffing the RAW WIFI signal.
AnalizadaCrítica (9.2)0.40%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.
AnalizadaAlta (8.7)0.46%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials.
AnalizadaAlta (7.1)0.53%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to invalidate a legitimate user's session and cause a denial-of-service attack on a user's account.
AnalizadaCrítica (9.3)0.67%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.
AnalizadaAlta (8.7)0.39%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone number and part of the email address.
AnalizadaAlta (7.1)0.43%—Ruijienetworks Reyee OS6/12/202417/6/2026
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services
AnalizadaMedia (6.3)0.41%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.
AnalizadaMedia (5.4)0.27%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including…
AnalizadaAlta (8)0.46%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (8.8)0.76%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist_new.php.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/tool/traceroute.php.
Orbitaley — Vulnerabilidades