Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

4192 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.31%—OpensslAIGlib-networking Glib NetworkingAI25/9/202530/6/2026
glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.
AplazadaMedia (6.8)0.32%—HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
AplazadaAlta (7.2)0.14%—HPE Aruba Networking EdgeconnectAIHPE Aruba Networking Edgeconnect Sd-wanAI16/9/202517/6/2026
A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized…
AplazadaAlta (7.2)0.64%—HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying…
AplazadaAlta (7.5)0.36%—HPE Aruba Networking Edgeconnect OSAI16/9/202517/6/2026
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
AplazadaAlta (8.6)0.40%—HPE Aruba Networking Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an attacker to route potentially harmful traffic through the internal network, leading to unauthorized access or disruption of services.
AplazadaAlta (8.8)0.47%—HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI16/9/202517/6/2026
A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying…
AplazadaAlta (8.8)0.18%—Megatek Azora Wireless Network ManagementAI16/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Network Management allows SQL Injection. This issue affects Azora Wireless Network Management: through 20250916. NOTE: The vendor did not inform about the completion of the…
AplazadaMedia (6.5)0.41%💥 ExploitCeragon Networks EtherhualAISiklu Communication MultihualAI15/9/202517/6/2026
On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in…
AplazadaAlta (7.2)0.18%—Paloaltonetworks User-id Credential AgentAI12/9/202517/6/2026
—
AplazadaBaja (2.4)0.14%—Microsoft 365 DefenderAIPaloaltonetworks Cortex XDRAI12/9/202517/6/2026
A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are…
AnalizadaAlta (8.8)0.65%—Monai Medical Open Network FOR AI9/9/202517/6/2026
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai/data/utils.py` automatically handles dictionary key-value pairs ending with a specific suffix and deserializes them using `pickle.loads()` . This function also…
AnalizadaAlta (8.8)0.76%—Monai Medical Open Network FOR AI9/9/202517/6/2026
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)` in monai/bundle/scripts.py , `weights_only=True` is loaded securely. However, insecure loading methods still…
AnalizadaAlta (8.8)0.63%—Monai Medical Open Network FOR AI9/9/202517/6/2026
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. It is used in many places in the project. In versions up to and including 1.5.0, when the Zip file containing malicious content is…
AnalizadaCrítica (9.8)2.4%💥 PoCMicrosoft Azure Networking4/9/202517/6/2026
Azure Networking Elevation of Privilege Vulnerability
AnalizadaAlta (8.8)0.32%—Cisco Evolved Programmable Network Manager3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An…
AnalizadaMedia (4.8)0.22%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists…
AnalizadaMedia (6.5)0.32%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system.
AplazadaAlta (8.7)1.1%—Spon Communications IP Network Broadcast SystemAI27/8/202517/6/2026
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory…
AplazadaCrítica (9)0.18%—Clininetworks ClininetworkAI27/8/202517/6/2026
Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges.
AplazadaMedia (5.3)0.21%—Nozominetworks CMCAI26/8/202517/6/2026
An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to…
AnalizadaBaja (2.1)7.7%—Dcnetworks Dcme-720 Firmware24/8/202517/6/2026
A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Management Backend. Performing manipulation of the argument ip results in os command injection. It is possible to initiate the attack remotely.…
AnalizadaMedia (6.5)0.42%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure20/8/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system on an affected device. This vulnerability is due to…
AplazadaAlta (8.7)1.1%💥 ExploitRealnetworks RealarcadeAIRealnetworks GamehouseAI20/8/202516/6/2026
The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions.…
AplazadaCrítica (9.3)0.49%💥 ExploitRealnetworks Netzip ClassicAI13/8/202516/6/2026
Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allows arbitrary code…