Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.46%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
AnalizadaAlta (8.8)0.63%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating…
AnalizadaAlta (8.8)0.54%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.
AnalizadaAlta (8.8)0.35%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute…
AnalizadaCrítica (9.1)1.5%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.
AnalizadaCrítica (9.8)1.0%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading…
AnalizadaCrítica (9.8)0.61%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the…
AnalizadaCrítica (9.9)0.53%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could…
AnalizadaCrítica (9.9)0.50%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
AnalizadaCrítica (9.9)0.50%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
Pendiente de análisisMedia (6.3)0.45%—Hyperledger Fabric CAAI15/9/202630/9/2026
Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping LDAP metacharacters. An unauthenticated…
AnalizadaAlta (7.8)0.20%—Microsoft Edge Chromium14/9/202625/9/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.1)0.41%—Microsoft Edge Chromium11/9/202625/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.66%—Microsoft EdgeMicrosoft Edge Chromium11/9/20266/10/2026
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
AplazadaMedia (5.5)0.51%—Hyperledger FireflyAI31/8/20261/9/2026
A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of…
AplazadaAlta (8.8)0.64%—Kubeedge CloudcoreAI29/8/202624/9/2026
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling.
AnalizadaAlta (8.8)0.82%—Microsoft Edge Chromium28/8/202611/9/2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.4)0.41%—Microsoft EdgeMicrosoft Edge Chromium28/8/20261/9/2026
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.21%—Microsoft Edge Chromium28/8/202631/8/2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaMedia (4.3)0.79%—Microsoft Edge Chromium28/8/202611/9/2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)0.92%—Microsoft Edge Chromium28/8/202611/9/2026
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.41%—Microsoft Edge Chromium28/8/202611/9/2026
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.4)0.39%—Microsoft Edge Chromium28/8/202611/9/2026
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
AnalizadaBaja (3)0.29%—Microsoft Edge Chromium28/8/202611/9/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.