Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+19 | 14/8/2024 | 17/6/2026 | When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Crítica (9) | 0.92% | — | Microsoft Edge Chromium | 12/8/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft Edge Chromium | 12/8/2024 | 17/6/2026 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | |
| Modificada | Media (5.9) | 0.45% | — | Microsoft Edge | 25/7/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | |
| Modificada | Alta (8.8) | 0.91% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 24/7/2024 | 17/6/2026 | An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Aplazada | Alta (7.2) | 0.75% | — | HPE Aruba Networking Edgeconnect Sd-wanAI | 24/7/2024 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the… | |
| Aplazada | Alta (7.2) | 0.68% | — | HPE Aruba Networking EdgeconnectAI | 24/7/2024 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the… | |
| Aplazada | Alta (7.2) | 0.75% | — | HPE Aruba Networking EdgeconnectAI | 24/7/2024 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the… | |
| Aplazada | Alta (7.2) | 0.70% | — | HPE Aruba Networking EdgeconnectAI | 24/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the… | |
| Analizada | Crítica (9.8) | 0.48% | — | Fabedge | 24/7/2024 | 17/6/2026 | Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | |
| Modificada | Media (6.1) | 0.30% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 24/7/2024 | 17/6/2026 | A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the… | |
| Modificada | Crítica (9) | 0.54% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 24/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Alta (8.8) | 0.78% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 24/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating… | |
| Modificada | Media (6) | 0.17% | — | Dell Edge Gateway 3200 FirmwareDell Edge Gateway 5200 FirmwareDell Precision 3930 Rack FirmwareDell Optiplex 7080 Firmware+6 | 24/7/2024 | 17/6/2026 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits. | |
| Modificada | Media (5.7) | 0.17% | — | Dell Edge Gateway 3200 Firmware | 24/7/2024 | 17/6/2026 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | |
| Modificada | Media (6.1) | 0.41% | — | Microsoft Edge | 19/7/2024 | 17/6/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Modificada | Alta (8.2) | 0.17% | — | Dell Edge Gateway 3200 FirmwareDell Edge Gateway 5200 Firmware | 10/7/2024 | 17/6/2026 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary code execution or escalation of… | |
| Modificada | Alta (8.2) | 0.17% | — | Dell Edge Gateway 5000 FirmwareDell Edge Gateway 5100 FirmwareDell Edge Gateway 5200 FirmwareDell Edge Gateway 3200 Firmware+2 | 10/7/2024 | 17/6/2026 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | |
| Modificada | Media (6.1) | 0.26% | — | SAP Netweaver Knowledge Management AND Collaboration (kmc-cm) | 9/7/2024 | 17/6/2026 | Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its… | |
| Modificada | Media (6.7) | 0.15% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+384 | 2/7/2024 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | |
| Modificada | Media (5.3) | 0.10% | — | Dell Poweredge R6615 FirmwareDell Poweredge R7615 FirmwareDell Poweredge R6625 FirmwareDell Poweredge R7625 Firmware+2 | 25/6/2024 | 17/6/2026 | Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources. | |
| Modificada | Media (4.3) | 0.50% | — | Microsoft Edge | 20/6/2024 | 20/7/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Modificada | Media (4.7) | 0.50% | — | Microsoft Edge | 20/6/2024 | 20/7/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| Modificada | Media (4.3) | 0.50% | — | Microsoft Edge Chromium | 13/6/2024 | 20/7/2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |