Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.48% | — | Fabian Nero Social Networking Site | 27/10/2025 | 17/6/2026 | A weakness has been identified in code-projects Nero Social Networking Site 1.0. This affects an unknown part of the file /friendprofile.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Nero Social Networking Site | 27/10/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of the argument message_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Nero Social Networking Site | 27/10/2025 | 17/6/2026 | A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an unknown functionality of the file /addfriend.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Nero Social Networking Site | 27/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the file /acceptoffres.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (3.7) | 0.36% | — | OpensslAIGnome Glib-networkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location. | |
| Aplazada | Media (4.8) | 0.31% | — | OpensslAIGlib-networking Glib NetworkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read. | |
| Aplazada | Media (6.8) | 0.32% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. | |
| Aplazada | Alta (7.2) | 0.14% | — | HPE Aruba Networking EdgeconnectAIHPE Aruba Networking Edgeconnect Sd-wanAI | 16/9/2025 | 17/6/2026 | A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized… | |
| Aplazada | Alta (7.2) | 0.64% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying… | |
| Aplazada | Alta (7.5) | 0.36% | — | HPE Aruba Networking Edgeconnect OSAI | 16/9/2025 | 17/6/2026 | A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly | |
| Aplazada | Alta (8.6) | 0.40% | — | HPE Aruba Networking Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an attacker to route potentially harmful traffic through the internal network, leading to unauthorized access or disruption of services. | |
| Aplazada | Alta (8.8) | 0.47% | — | HPE Aruba Networking Edgeconnect Sd-wan GatewaysAI | 16/9/2025 | 17/6/2026 | A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying… | |
| Analizada | Crítica (9.8) | 2.4% | 💥 PoC | Microsoft Azure Networking | 4/9/2025 | 17/6/2026 | Azure Networking Elevation of Privilege Vulnerability | |
| Aplazada | Crítica (9.8) | 1.1% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system. | |
| Aplazada | Alta (7.2) | 1.5% | — | HPE Networking Instant ON Access PointsAI | 8/7/2025 | 17/6/2026 | An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user. | |
| Aplazada | Alta (7.7) | 0.48% | — | HPE Aruba Networking Private 5G CoreAI | 10/6/2025 | 17/6/2026 | A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information. | |
| Analizada | Media (5.6) | 0.27% | — | Opennetworking Onos | 29/5/2025 | 17/6/2026 | An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets. | |
| Analizada | Crítica (9.8) | 0.40% | — | Opennetworking Onos | 29/5/2025 | 17/6/2026 | An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-middle attack on communications between fake and real hosts. | |
| Analizada | Media (6.9) | 0.63% | — | Fabian Nero Social Networking Site | 4/5/2025 | 17/6/2026 | A vulnerability was found in code-projects Nero Social Networking Site 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument fname/lname/login/password2/cpassword/address/cnumber/email/gender/propic/month leads to sql injection. It is possible to… | |
| Aplazada | Media (5.5) | 0.14% | — | HPE Aruba Networking Virtual Intranet AccessAIMicrosoft WindowsAI | 1/4/2025 | 17/6/2026 | A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This… | |
| Analizada | Crítica (9.1) | 0.48% | — | Opennetworking Onos | 24/3/2025 | 17/6/2026 | An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct. | |
| Analizada | Alta (7.5) | 0.37% | — | Opennetworking Onos | 24/3/2025 | 17/6/2026 | Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets. | |
| Analizada | Crítica (9.8) | 0.56% | — | Opennetworking Onos | 24/3/2025 | 17/6/2026 | An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information. | |
| Aplazada | Media (6.2) | 0.16% | — | Open Networking Foundation Sd-ran OnosAILinuxfoundation Onos-lib-goAI | 16/3/2025 | 17/6/2026 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits. | |
| Analizada | Alta (7.5) | 0.60% | — | Opennetworking Onos-a1tOpennetworking Sdran-in-a-box | 4/11/2024 | 17/6/2026 | An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specifically the DeleteWatcher function. |