Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.44%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1914/8/202417/6/2026
When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.48%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1714/8/202417/6/2026
When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaCrítica (9)0.92%—Microsoft Edge Chromium12/8/202417/6/2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AnalizadaAlta (7.8)0.61%—Microsoft Edge Chromium12/8/202417/6/2026
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
ModificadaMedia (5.9)0.45%—Microsoft Edge25/7/202417/6/2026
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
ModificadaAlta (8.8)0.91%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
AplazadaAlta (7.2)0.75%—HPE Aruba Networking Edgeconnect Sd-wanAI24/7/202417/6/2026
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the…
AplazadaAlta (7.2)0.68%—HPE Aruba Networking EdgeconnectAI24/7/202417/6/2026
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the…
AplazadaAlta (7.2)0.75%—HPE Aruba Networking EdgeconnectAI24/7/202417/6/2026
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the…
AplazadaAlta (7.2)0.70%—HPE Aruba Networking EdgeconnectAI24/7/202417/6/2026
A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the…
AnalizadaCrítica (9.8)0.48%—Fabedge24/7/202417/6/2026
Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
ModificadaMedia (6.1)0.30%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the…
ModificadaCrítica (9)0.54%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaAlta (8.8)0.78%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating…
ModificadaMedia (6)0.17%—Dell Edge Gateway 3200 FirmwareDell Edge Gateway 5200 FirmwareDell Precision 3930 Rack FirmwareDell Optiplex 7080 Firmware+624/7/202417/6/2026
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits.
ModificadaMedia (5.7)0.17%—Dell Edge Gateway 3200 Firmware24/7/202417/6/2026
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
ModificadaMedia (6.1)0.41%—Microsoft Edge19/7/202417/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
ModificadaAlta (8.2)0.17%—Dell Edge Gateway 3200 FirmwareDell Edge Gateway 5200 Firmware10/7/202417/6/2026
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary code execution or escalation of…
ModificadaAlta (8.2)0.17%—Dell Edge Gateway 5000 FirmwareDell Edge Gateway 5100 FirmwareDell Edge Gateway 5200 FirmwareDell Edge Gateway 3200 Firmware+210/7/202417/6/2026
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
ModificadaMedia (6.1)0.26%—SAP Netweaver Knowledge Management AND Collaboration (kmc-cm)9/7/202417/6/2026
Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its…
ModificadaMedia (6.7)0.15%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+3842/7/202417/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
ModificadaMedia (5.3)0.10%—Dell Poweredge R6615 FirmwareDell Poweredge R7615 FirmwareDell Poweredge R6625 FirmwareDell Poweredge R7625 Firmware+225/6/202417/6/2026
Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.
ModificadaMedia (4.3)0.50%—Microsoft Edge20/6/202420/7/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
ModificadaMedia (4.7)0.50%—Microsoft Edge20/6/202420/7/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
ModificadaMedia (4.3)0.50%—Microsoft Edge Chromium13/6/202420/7/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability