Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

556 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.59%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an…
AnalizadaAlta (8.2)0.69%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system.
AnalizadaAlta (8.5)0.35%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to…
AnalizadaAlta (8.5)0.36%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host…
AnalizadaAlta (8.6)0.46%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
AnalizadaAlta (8.8)0.63%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating…
AnalizadaAlta (8.8)0.54%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.
AnalizadaAlta (8.8)0.35%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute…
AnalizadaCrítica (9.1)1.5%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.
AnalizadaCrítica (9.8)1.0%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading…
AnalizadaCrítica (9.8)0.61%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the…
AnalizadaCrítica (9.9)0.53%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could…
AnalizadaCrítica (9.9)0.50%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
AnalizadaCrítica (9.9)0.50%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
AnalizadaAlta (8.1)0.36%—Oracle JD Edwards Enterpriseone Orchestrator18/8/202627/8/2026
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards…
AnalizadaAlta (8.1)0.39%—Oracle JD Edwards Enterpriseone Orchestrator18/8/202627/8/2026
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise JD Edwards…
Pendiente de análisisAlta (8.7)0.52%—Lenovo Xclarity OrchestratorAI4/8/202624/8/2026
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
Pendiente de análisisAlta (7)0.11%—Lenovo Xclarity OrchestratorAI4/8/202624/8/2026
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation…
Pendiente de análisisCrítica (9.8)0.80%—HPE Networking Sd-wan OrchestratorAI4/8/20266/8/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target…
Pendiente de análisisCrítica (9.8)0.80%—HPE Networking Sd-wan OrchestratorAI4/8/20266/8/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target…
Pendiente de análisisAlta (8.5)0.35%—Arista OrchestratorAI27/7/202630/7/2026
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network…
AnalizadaCrítica (10)1.0%⚠ Explotación activaArista Velocloud Orchestrator27/7/202628/7/2026
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.…
Pendiente de análisisAlta (7.5)0.44%—Vllm-orchestrator-gatewayAI13/7/202613/7/2026
A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be…
AplazadaMedia (5.3)0.35%—Enderfga Claw OrchestratorAI1/6/202622/7/2026
A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the component Session Grep Endpoint. The manipulation of the argument body.pattern leads to inefficient regular expression…