Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.34% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system. | |
| Analizada | Media (4.9) | 0.44% | — | HPE Arubaos-cx | 1/9/2026 | 5/10/2026 | Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system. | |
| Analizada | Alta (8.3) | 0.20% | — | HPE Arubaos-cx | 1/9/2026 | 22/9/2026 | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of… | |
| Analizada | Media (6.5) | 0.29% | — | HPE Arubaos-cx | 1/9/2026 | 22/9/2026 | Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices. | |
| Analizada | Alta (8.8) | 0.66% | — | HPE Arubaos-cx | 1/9/2026 | 22/9/2026 | Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (8.8) | 0.47% | — | HPE Arubaos-cx | 1/9/2026 | 22/9/2026 | An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. | |
| Analizada | Alta (8.8) | 0.66% | — | HPE Arubaos-cx | 1/9/2026 | 22/9/2026 | An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 0.80% | — | HPE Arubaos-cx | 1/9/2026 | 22/9/2026 | Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a… | |
| Analizada | Crítica (9.8) | 0.82% | — | HPE Arubaos-cx | 1/9/2026 | 22/9/2026 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with… | |
| Analizada | Alta (7.2) | 0.87% | — | HPE Arubaos-cx | 21/7/2026 | 11/8/2026 | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution. | |
| Analizada | Alta (7.2) | 0.62% | — | HPE Arubaos-cx | 21/7/2026 | 11/8/2026 | Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system. | |
| Analizada | Alta (8.8) | 0.75% | — | HPE Arubaos-cx | 21/7/2026 | 11/8/2026 | A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system. | |
| Analizada | Alta (8.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Media (4.9) | 0.51% | — | Arubanetworks Arubaos | 12/5/2026 | 17/6/2026 | A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of confidential system information, potentially… | |
| Analizada | Media (5.4) | 0.23% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration. An attacker with compromised credentials… | |
| Analizada | Alta (7.2) | 1.2% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device. | |
| Analizada | Alta (8.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.5% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… | |
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… | |
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… |