Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.56%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN…
ModificadaMedia (6.1)0.48%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)1.0%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (8.1)0.79%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaAlta (7.2)1.1%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system…
ModificadaAlta (7.2)1.3%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating…
ModificadaAlta (7.5)0.47%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.
ModificadaMedia (6.1)0.49%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaAlta (8.1)0.86%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaMedia (5.4)0.53%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaBaja (2.7)0.66%—Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+1013/4/202217/6/2026
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
ModificadaMedia (6.5)1.2%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WAN Orchestrator user may inject code into SQL queries which may lead to information disclosure.
ModificadaAlta (7.2)1.6%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator user with high privileges may be able to execute arbitrary code on the underlying operating system.
ModificadaCrítica (9.8)2.9%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.
ModificadaAlta (8.8)43%—Vmware Sd-wan Orchestrator24/11/202017/6/2026
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal. An authenticated SD-WAN Orchestrator user is able to traversal directories which may lead to code execution of files.