Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
39.978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.8) | 0.53% | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent. | |
| Recibida | Crítica (9.8) | 0.53% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system. | |
| Recibida | Crítica (9.1) | 0.45% | — | — | 6/10/2026 | 6/10/2026 | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device. | |
| Recibida | Crítica (9.3) | 0.20% | — | — | 6/10/2026 | 6/10/2026 | An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device. | |
| Recibida | Crítica (9.6) | 0.24% | — | — | 6/10/2026 | 6/10/2026 | Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code. | |
| Recibida | Crítica (9.8) | 0.51% | — | — | 6/10/2026 | 6/10/2026 | Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code. | |
| Recibida | Crítica (9.8) | 0.56% | — | Aos-sAI | 6/10/2026 | 6/10/2026 | A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain… | |
| Recibida | Crítica (9.8) | 0.59% | — | Aos-sAI | 6/10/2026 | 7/10/2026 | Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system. | |
| Pendiente de análisis | Crítica (9.8) | 0.64% | — | Handlebarsjs HandlebarsAI | 6/10/2026 | 7/10/2026 | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation… | |
| Pendiente de análisis | Crítica (9.2) | 0.41% | — | Handlebarsjs HandlebarsAI | 6/10/2026 | 7/10/2026 | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled… | |
| Pendiente de análisis | Crítica (9) | 0.23% | — | Arista WI FI Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access… | |
| Pendiente de análisis | Crítica (9.4) | 0.25% | — | Arista Wi-fi Access PointsAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition… | |
| Pendiente de análisis | Crítica (9.3) | 0.36% | — | Cv-cueAI | 6/10/2026 | 7/10/2026 | An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services. | |
| Pendiente de análisis | Crítica (9.3) | 0.28% | — | CloudvisionAI | 6/10/2026 | 7/10/2026 | A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their… | |
| Pendiente de análisis | Crítica (9.3) | 0.22% | — | — | 6/10/2026 | 7/10/2026 | A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session,… | |
| Pendiente de análisis | Crítica (9.6) | 0.63% | — | Dell System UpdateAI | 6/10/2026 | 6/10/2026 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is… | |
| Pendiente de análisis | Crítica (9.8) | 0.30% | — | — | 6/10/2026 | 7/10/2026 | In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.6) | 0.30% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.30% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Crítica (9.6) | 0.30% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 0.30% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 0.35% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| Analizada | Crítica (9.6) | 0.36% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 0.31% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Pendiente de análisis | Crítica (9.6) | 0.44% | — | Google ChromeAI | 6/10/2026 | 7/10/2026 | Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |