Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

1847 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)12%—Ruijienetworks Bcr810w Firmware10/7/202317/6/2026
A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (7.5)0.64%—Arubanetworks Arubaos5/7/202317/6/2026
There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the controller.
ModificadaMedia (6.1)0.46%—Arubanetworks Arubaos5/7/202317/6/2026
A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected…
ModificadaMedia (6.5)0.55%—Arubanetworks Arubaos5/7/202317/6/2026
Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
ModificadaMedia (6.5)0.55%—Arubanetworks Arubaos5/7/202317/6/2026
Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
ModificadaAlta (8.1)0.72%—Arubanetworks Arubaos5/7/202317/6/2026
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.
ModificadaAlta (7.2)1.4%—Arubanetworks Arubaos5/7/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.4%—Arubanetworks Arubaos5/7/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.6%—Arubanetworks Arubaos5/7/202317/6/2026
An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the…
ModificadaMedia (6.1)0.62%—Arubanetworks Arubaos5/7/202317/6/2026
A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the…
ModificadaAlta (7.8)0.30%—ARM NN Android Neural Networks Driver29/6/202317/6/2026
A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Android-NN-Driver before 23.02.
ModificadaCrítica (9.8)0.94%—L7-networks InstantqosL7-networks Instantscan16/6/202317/6/2026
La función de carga de archivos de L7 Networks InstantScan IS-8000 e InstantQoS IQ-8000 no restringen la carga de archivos de tipo peligroso. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para cargar y ejecutar archivos ejecutables arbitrarios para realizar comandos arbitrarios del sistema o…
ModificadaMedia (5.4)0.37%—Paloaltonetworks Pan-os14/6/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.
ModificadaAlta (7.8)0.18%—Paloaltonetworks Globalprotect14/6/202317/6/2026
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitVmware Aria Operations FOR Networks7/6/202317/6/2026
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
ModificadaAlta (8.8)1.5%—Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+1422/5/202317/6/2026
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that…
ModificadaAlta (8.8)1.1%—Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+1422/5/202317/6/2026
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change…
ModificadaMedia (4.3)0.58%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data…
ModificadaMedia (6.5)0.65%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
ModificadaMedia (6.5)0.65%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
ModificadaMedia (6.5)0.65%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
ModificadaAlta (8.8)1.1%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.0%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.0%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.0%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…