Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… | |
| Analizada | Alta (7.2) | 0.58% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests… | |
| Analizada | Alta (7.2) | 1.6% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user. | |
| Analizada | Alta (7.2) | 1.6% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user. | |
| Modificada | Alta (7.2) | 0.61% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input… | |
| Analizada | Alta (7.5) | 0.53% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying… | |
| Analizada | Alta (7.5) | 0.40% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation could cause the… | |
| Analizada | Alta (7.5) | 0.33% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical… | |
| Analizada | Alta (7.5) | 0.33% | — | Arubanetworks ArubaosArubanetworks Sd-wan | 12/5/2026 | 17/6/2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical… | |
| Analizada | Alta (7.2) | 0.96% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points… | |
| Analizada | Media (5.3) | 0.26% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced… | |
| Analizada | Alta (7.2) | 0.62% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note:… | |
| Analizada | Alta (7.2) | 0.56% | — | Arubanetworks Arubaos | 12/5/2026 | 12/8/2026 | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 0.27% | — | Arubanetworks Arubaos | 12/5/2026 | 11/8/2026 | A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and… | |
| Analizada | Media (6.1) | 0.29% | — | HPE Arubaos-cx | 11/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL. | |
| Analizada | Alta (8.8) | 1.2% | — | HPE Arubaos-cx | 11/3/2026 | 22/9/2026 | A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (7.2) | 0.94% | — | HPE Arubaos-cx | 11/3/2026 | 22/9/2026 | A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands. | |
| Analizada | Alta (8.8) | 0.56% | — | HPE Arubaos-cx | 11/3/2026 | 22/9/2026 | A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior. | |
| Analizada | Crítica (9.8) | 0.74% | 💥 PoC | HPE Arubaos-cx | 11/3/2026 | 22/9/2026 | A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password. | |
| Analizada | Media (4.2) | 0.15% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for the interception or modification of… |