Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.31% | — | OpensslAIGlib-networking Glib NetworkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read. | |
| Aplazada | Media (6.8) | 0.32% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. | |
| Aplazada | Alta (7.2) | 0.14% | — | HPE Aruba Networking EdgeconnectAIHPE Aruba Networking Edgeconnect Sd-wanAI | 16/9/2025 | 17/6/2026 | A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized… | |
| Aplazada | Alta (7.2) | 0.64% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying… | |
| Aplazada | Alta (7.5) | 0.36% | — | HPE Aruba Networking Edgeconnect OSAI | 16/9/2025 | 17/6/2026 | A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly | |
| Aplazada | Alta (8.6) | 0.40% | — | HPE Aruba Networking Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an attacker to route potentially harmful traffic through the internal network, leading to unauthorized access or disruption of services. | |
| Aplazada | Alta (8.8) | 0.47% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying… | |
| Aplazada | Alta (8.8) | 0.18% | — | Megatek Azora Wireless Network ManagementAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Network Management allows SQL Injection. This issue affects Azora Wireless Network Management: through 20250916. NOTE: The vendor did not inform about the completion of the… | |
| Aplazada | Media (6.5) | 0.41% | 💥 Exploit | Ceragon Networks EtherhualAISiklu Communication MultihualAI | 15/9/2025 | 17/6/2026 | On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in… | |
| Aplazada | Alta (7.2) | 0.18% | — | Paloaltonetworks User-id Credential AgentAI | 12/9/2025 | 17/6/2026 | — | |
| Aplazada | Baja (2.4) | 0.14% | — | Microsoft 365 DefenderAIPaloaltonetworks Cortex XDRAI | 12/9/2025 | 17/6/2026 | A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are… | |
| Analizada | Alta (8.8) | 0.65% | — | Monai Medical Open Network FOR AI | 9/9/2025 | 17/6/2026 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai/data/utils.py` automatically handles dictionary key-value pairs ending with a specific suffix and deserializes them using `pickle.loads()` . This function also… | |
| Analizada | Alta (8.8) | 0.76% | — | Monai Medical Open Network FOR AI | 9/9/2025 | 17/6/2026 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)` in monai/bundle/scripts.py , `weights_only=True` is loaded securely. However, insecure loading methods still… | |
| Analizada | Alta (8.8) | 0.63% | — | Monai Medical Open Network FOR AI | 9/9/2025 | 17/6/2026 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. It is used in many places in the project. In versions up to and including 1.5.0, when the Zip file containing malicious content is… | |
| Analizada | Crítica (9.8) | 2.4% | 💥 PoC | Microsoft Azure Networking | 4/9/2025 | 17/6/2026 | Azure Networking Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 0.32% | — | Cisco Evolved Programmable Network Manager | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An… | |
| Analizada | Media (4.8) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists… | |
| Analizada | Media (6.5) | 0.32% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system. | |
| Aplazada | Alta (8.7) | 1.1% | — | Spon Communications IP Network Broadcast SystemAI | 27/8/2025 | 17/6/2026 | SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory… | |
| Aplazada | Crítica (9) | 0.18% | — | Clininetworks ClininetworkAI | 27/8/2025 | 17/6/2026 | Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges. | |
| Aplazada | Media (5.3) | 0.21% | — | Nozominetworks CMCAI | 26/8/2025 | 17/6/2026 | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to… | |
| Analizada | Baja (2.1) | 7.7% | — | Dcnetworks Dcme-720 Firmware | 24/8/2025 | 17/6/2026 | A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Management Backend. Performing manipulation of the argument ip results in os command injection. It is possible to initiate the attack remotely.… | |
| Analizada | Media (6.5) | 0.42% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 20/8/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system on an affected device. This vulnerability is due to… | |
| Aplazada | Alta (8.7) | 1.1% | 💥 Exploit | Realnetworks RealarcadeAIRealnetworks GamehouseAI | 20/8/2025 | 16/6/2026 | The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions.… | |
| Aplazada | Crítica (9.3) | 0.49% | 💥 Exploit | Realnetworks Netzip ClassicAI | 13/8/2025 | 16/6/2026 | Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allows arbitrary code… |