Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

1845 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (7.2)1.1%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system…
ModificadaAlta (7.2)1.3%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating…
ModificadaAlta (7.5)0.47%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.
ModificadaMedia (6.1)0.49%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaAlta (8.1)0.86%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaAlta (8.8)58%💥 ExploitRuijienetworks Rg-ew1200g Firmware18/8/202317/6/2026
A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be…
ModificadaMedia (5.3)0.55%—Nozominetworks CMCNozominetworks Guardian9/8/202317/6/2026
Se ha detectado una vulnerabilidad de denegación de servicio parcial en la sección Informes, que puede ser explotada por un usuario malicioso ya autenticado que fuerce a guardar un informe con el nombre nulo. La sección de informes estará parcialmente no disponible para todos los intentos posteriores de utilizarla,…
ModificadaMedia (6.9)0.60%—Nozominetworks CMCNozominetworks Guardian9/8/202317/6/2026
Un administrador autenticado puede cargar un archivo de configuración SAML con el formato incorrecto, sin que la aplicación compruebe el formato correcto del archivo. Cada solicitud posterior de la aplicación devolverá un error. Toda la aplicación en inutilizable hasta una intervención de la consola.
ModificadaAlta (7.1)0.48%—Nozominetworks CMCNozominetworks Guardian9/8/202317/6/2026
Se ha encontrado una vulnerabilidad en el control de acceso, debido a que las restricciones que se aplican en las aserciones reales no se aplican en su funcionalidad de depuración. Un usuario autenticado con visibilidad reducida puede obtener información no autorizada a través de la funcionalidad de depuración,…
AnalizadaAlta (8.7)0.61%—Nozominetworks CMCNozominetworks Guardian9/8/202317/6/2026
Una vulnerabilidad de inyección blind SQL en Nozomi Networks Guardian y CMC, debida a una validación de entrada incorrecta en el componente alerts_count, permite a un atacante autenticado ejecutar consultas SQL arbitrarias en el DBMS utilizado por la aplicación web. Los usuarios autenticados pueden extraer información…
ModificadaAlta (7.3)0.33%—Nozominetworks CMCNozominetworks Guardian9/8/202317/6/2026
Un atacante autenticado con acceso administrativo al dispositivo puede inyectar código JavaScript malicioso dentro de la definición de una regla de Inteligencia de Amenazas, que posteriormente será ejecutado por otro usuario legítimo que vea los detalles de dicha regla. Un atacante puede ser capaz de realizar acciones…
ModificadaAlta (8.7)0.61%—Nozominetworks CMCNozominetworks Guardian9/8/202317/6/2026
Una vulnerabilidad de inyección blind SQL en Guardian y CMC de Nozomi Networks, debido a una validación de entrada incorrecta en el parámetro de ordenación, permite a un atacante autenticado ejecutar consultas SQL arbitrarias en el DBMS utilizado por la aplicación web. Los usuarios autenticados pueden extraer…
ModificadaMedia (5.4)0.15%—Nozominetworks CMCNozominetworks Guardian9/8/202317/6/2026
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.
ModificadaCrítica (9.8)2.1%—Arubanetworks ArubaosHP Instantos25/7/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability…
ModificadaCrítica (9.8)2.1%—Arubanetworks ArubaosHP Instantos25/7/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability…
ModificadaCrítica (9.8)2.1%—Arubanetworks ArubaosHP Instantos25/7/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability…
ModificadaCrítica (9.8)1.1%—Extremenetworks IQ Engine15/7/202317/6/2026
IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.
ModificadaMedia (4.9)0.46%—Paloaltonetworks Pan-os12/7/202317/6/2026
A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system.
ModificadaAlta (8.8)12%—Ruijienetworks Bcr810w Firmware10/7/202317/6/2026
A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (7.5)0.64%—Arubanetworks Arubaos5/7/202317/6/2026
There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the controller.