Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.46% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations. | |
| Analizada | Alta (8.8) | 0.63% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating… | |
| Analizada | Alta (8.8) | 0.54% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise. | |
| Analizada | Alta (8.8) | 0.35% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute… | |
| Analizada | Crítica (9.1) | 1.5% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise. | |
| Analizada | Crítica (9.8) | 1.0% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading… | |
| Analizada | Crítica (9.8) | 0.61% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the… | |
| Analizada | Crítica (9.9) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could… | |
| Analizada | Crítica (9.9) | 0.50% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise. | |
| Analizada | Crítica (9.9) | 0.50% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise. | |
| Pendiente de análisis | Media (6.3) | 0.45% | — | Hyperledger Fabric CAAI | 15/9/2026 | 30/9/2026 | Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping LDAP metacharacters. An unauthenticated… | |
| Analizada | Alta (7.8) | 0.20% | — | Microsoft Edge Chromium | 14/9/2026 | 25/9/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Edge Chromium | 11/9/2026 | 25/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.66% | — | Microsoft EdgeMicrosoft Edge Chromium | 11/9/2026 | 6/10/2026 | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Media (5.5) | 0.51% | — | Hyperledger FireflyAI | 31/8/2026 | 1/9/2026 | A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of… | |
| Aplazada | Alta (8.8) | 0.64% | — | Kubeedge CloudcoreAI | 29/8/2026 | 24/9/2026 | KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Edge Chromium | 28/8/2026 | 11/9/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 0.41% | — | Microsoft EdgeMicrosoft Edge Chromium | 28/8/2026 | 1/9/2026 | Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.21% | — | Microsoft Edge Chromium | 28/8/2026 | 31/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Media (4.3) | 0.79% | — | Microsoft Edge Chromium | 28/8/2026 | 11/9/2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Edge Chromium | 28/8/2026 | 11/9/2026 | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.41% | — | Microsoft Edge Chromium | 28/8/2026 | 11/9/2026 | Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 0.39% | — | Microsoft Edge Chromium | 28/8/2026 | 11/9/2026 | Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Baja (3) | 0.29% | — | Microsoft Edge Chromium | 28/8/2026 | 11/9/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. |