Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
5318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged… | |
| Analizada | Alta (7.2) | 0.43% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system. | |
| Analizada | Alta (7.2) | 1.3% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.3% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system. | |
| Analizada | Crítica (9.1) | 0.44% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in… | |
| Analizada | Baja (2.3) | 0.24% | — | Wikiworks Approved Revs | 9/1/2026 | 17/6/2026 | Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Media (4.9) | 0.14% | — | Hetworks Wp-image-shrinkerAI | 29/12/2025 | 7/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through <= 1.1.0. | |
| Analizada | Alta (8.5) | 0.11% | — | Versa-networks Sase Client | 20/12/2025 | 7/10/2026 | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user.… | |
| Aplazada | Alta (8.2) | 0.57% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric MC Works64AI | 19/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") of Mitsubishi Electric GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions… | |
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device… | |
| Modificada | Media (5.3) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and… | |
| Modificada | Alta (7.1) | 0.26% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a malicious report… | |
| Modificada | Baja (2.3) | 0.18% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 30/9/2026 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots.… | |
| Aplazada | Alta (8.6) | 1.4% | — | Ruijienetworks RG Ap180AI | 18/12/2025 | 7/10/2026 | RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service. | |
| Analizada | Crítica (9.2) | 0.31% | — | Ruijienetworks Reyee OS | 15/12/2025 | 17/6/2026 | ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the… | |
| Analizada | Alta (8.8) | 2.8% | — | Ruijienetworks Reyee OSRuijie Rg-rap2200(e) Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Contact FormAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Request Forgery.This issue affects Quick Contact Form: from n/a through <= 8.2.5. | |
| Analizada | Crítica (9.8) | 3.4% | ⚠ Explotación activa | Arraynetworks Arrayos AG | 5/12/2025 | 17/6/2026 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. | |
| Aplazada | Media (6.4) | 0.18% | — | Redhat Codeready WorkspacesAI | 2/12/2025 | 17/6/2026 | A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can… | |
| Analizada | Alta (8.8) | 0.74% | — | Accellion Kiteworks | 29/11/2025 | 7/10/2026 | Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly elevate another user's permissions on the share. This issue has been patched in version 9.1.0. | |
| Analizada | Alta (8.8) | 1.1% | — | Accellion Kiteworks Managed File Transfer | 29/11/2025 | 7/10/2026 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for authorized users. This issue has been patched in version 9.1.0. | |
| Analizada | Alta (7.2) | 0.94% | — | Accellion Kiteworks Managed File Transfer | 29/11/2025 | 7/10/2026 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream… | |
| Analizada | Media (6.8) | 0.20% | — | Accellion Kiteworks Managed File Transfer | 29/11/2025 | 7/10/2026 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT. This issue has been patched in… |