Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9)0.54%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaAlta (8.8)0.78%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating…
ModificadaMedia (5.3)0.56%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN…
ModificadaMedia (6.1)0.48%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)1.0%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (7.2)1.1%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system…
ModificadaAlta (7.2)1.3%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating…
ModificadaAlta (7.5)0.47%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.
ModificadaMedia (6.1)0.49%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaAlta (8.1)0.86%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaMedia (4.9)1.7%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
ModificadaMedia (6.1)0.82%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
ModificadaAlta (7.2)1.8%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
Orbitaley — Vulnerabilidades