Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 1.0% | — | Microsoft Edge Chromium | 15/9/2023 | 17/6/2026 | Vulnerabilidad de Elevación de Privilegios en Microsoft Edge (basado en Chromium) | |
| Modificada | Media (6.7) | 0.17% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+48 | 15/9/2023 | 17/6/2026 | Dell PowerEdge BIOS y Dell Precision BIOS contiene una vulnerabilidad de desbordamiento del búfer. Un usuario local malicioso con altos privilegios podría explotar potencialmente esta vulnerabilidad, lo que provocaría una corrupción de la memoria y potencialmente escalaría privilegios. | |
| Modificada | Media (6.1) | 0.57% | — | Openknowledgemaps Head Start | 13/9/2023 | 17/6/2026 | Una vulnerabilidad Cross-Site Scripting (XSS) Reflejada en OpenKnowledgeMaps Head Start 7 permite a atacantes remotos ejecutar JavaScript arbitrario en el navegador web de un usuario, al incluir un payload malicioso en el parámetro 'file' en 'displayPDF.php'. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraDebian LinuxMozilla Firefox+8 | 12/9/2023 | 17/6/2026 | El desbordamiento del búfer de memoria en libwebp en Google Chrome anterior a 116.0.5845.187 y libwebp 1.3.2 permitía a un atacante remoto realizar una escritura en memoria fuera de los límites a través de una página HTML manipulada. (Severidad de seguridad de Chromium: crítica) | |
| Analizada | Alta (8.8) | 41% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxFedoraproject FedoraMicrosoft Edge Chromium | 5/9/2023 | 17/6/2026 | Type Confusion en V8 en Google Chrome anterior a 116.0.5845.179 permitía a un atacante remoto ejecutar código arbitrario a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta) | |
| Modificada | Alta (7.5) | 2.1% | — | Microsoft Edge Chromium | 26/8/2023 | 10/8/2026 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 0.56% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN… | |
| Modificada | Media (6.1) | 0.48% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Media (6.5) | 0.77% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Media (6.5) | 0.77% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Media (6.5) | 0.77% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Media (6.5) | 0.77% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 1.0% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (7.2) | 1.1% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system… | |
| Modificada | Alta (7.2) | 1.3% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating… | |
| Modificada | Alta (7.5) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host. | |
| Modificada | Media (6.1) | 0.49% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Alta (8.1) | 0.86% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… |