Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.35% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits. | |
| Analizada | Media (4.9) | 0.35% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits. | |
| Analizada | Media (6.5) | 0.36% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system. | |
| Analizada | Media (6.5) | 0.36% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system. | |
| Analizada | Media (6.5) | 0.36% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system. | |
| Analizada | Alta (7.2) | 1.2% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.2% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 14/10/2025 | 17/6/2026 | An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating… | |
| Analizada | Media (6.2) | 0.66% | — | Arubanetworks Arubaos | 14/10/2025 | 30/9/2026 | An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor… | |
| Analizada | Baja (2.4) | 0.20% | — | Ericsson Network Manager | 13/10/2025 | 17/6/2026 | Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains. | |
| Analizada | Media (6.9) | 0.30% | — | Ericsson Network Manager | 13/10/2025 | 17/6/2026 | Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege. | |
| Aplazada | Baja (2.1) | 0.25% | — | Ipynch Social Network WebsiteAI | 11/10/2025 | 17/6/2026 | A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The affected element is an unknown function of the component Search. Performing manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to… | |
| Modificada | Media (5.5) | 0.79% | 💥 PoC | Paloaltonetworks Pan-os | 9/10/2025 | 17/6/2026 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted… | |
| Analizada | Media (4.8) | 0.26% | — | Paloaltonetworks Pan-os | 9/10/2025 | 17/6/2026 | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked. The security risk posed by this issue is significantly… | |
| Analizada | Alta (8.4) | 0.35% | — | Extremenetworks Fabric Engine (voss) | 7/10/2025 | 17/6/2026 | A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing… | |
| Analizada | Alta (7.2) | 0.41% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their… | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.7) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS used by the web application, potentially exposing unauthorized data, altering their structure and… | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.2) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device configuration, and/or affecting its… | |
| Analizada | Media (5.9) | 0.22% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack. | |
| Analizada | Alta (7.6) | 0.34% | — | Extremenetworks Extremeguest Essentials | 1/10/2025 | 17/6/2026 | In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an unauthenticated device to be marked as authenticated and obtain network access.… | |
| Analizada | Alta (7.5) | 0.34% | — | Stormshield Network Security | 25/9/2025 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing. | |
| Aplazada | Baja (3.7) | 0.36% | — | OpensslAIGnome Glib-networkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location. |