Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted… | |
| Analizada | Alta (7.2) | 0.50% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying… | |
| Analizada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged… | |
| Analizada | Alta (7.2) | 0.43% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system. | |
| Analizada | Alta (7.2) | 1.3% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.3% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system. | |
| Analizada | Crítica (9.1) | 0.44% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in… | |
| Aplazada | Alta (7.5) | 0.46% | — | HPE Networking Instant ON Access PointsAI | 13/1/2026 | 17/6/2026 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a… | |
| Aplazada | Alta (8.6) | 0.05% | — | Kings Information & Network Kess EnterpriseAI | 29/12/2025 | 7/10/2026 | Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privilege Escalation, Modify Existing Service, Modify Shared File.This issue affects… | |
| Analizada | Alta (8.5) | 0.11% | — | Versa-networks Sase Client | 20/12/2025 | 7/10/2026 | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user.… | |
| Modificada | Alta (7.5) | 0.42% | — | Opennetworking UPF | 18/12/2025 | 5/7/2026 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment Request that includes a CreateFAR with an empty or truncated IPv4 address field is not properly validated. During parsing, parseFAR() calls… | |
| Analizada | Alta (7.5) | 0.41% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Flow-Description… | |
| Analizada | Alta (7.5) | 0.41% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Request that is missing the mandatory F-SEID (CPF-SEID) Information Element is not properly validated. The session… | |
| Analizada | Alta (7.5) | 0.43% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler dereferences a nil pointer via… | |
| Analizada | Alta (7.5) | 0.44% | — | Opennetworking UPF | 18/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferences a nil pointer… | |
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device… | |
| Modificada | Media (5.3) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and… | |
| Modificada | Alta (7.1) | 0.26% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a malicious report… | |
| Modificada | Baja (2.3) | 0.18% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 30/9/2026 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots.… | |
| Aplazada | Alta (8.6) | 1.4% | — | Ruijienetworks RG Ap180AI | 18/12/2025 | 7/10/2026 | RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service. | |
| Analizada | Crítica (9.2) | 0.31% | — | Ruijienetworks Reyee OS | 15/12/2025 | 17/6/2026 | ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the… | |
| Aplazada | Alta (8.7) | 0.90% | — | APC Network Management Card 4AI | 11/12/2025 | 17/6/2026 | APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like /etc/passwd by using encoded path traversal characters in… | |
| Analizada | Alta (8.8) | 2.8% | — | Ruijienetworks Reyee OSRuijie Rg-rap2200(e) Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. |