Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.1) | 0.16% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a port-stealing attack - may enable a bi-directional… | |
| Analizada | Baja (3.1) | 0.19% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with the victim's BSSID. Successful… | |
| Analizada | Alta (7.6) | 0.27% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSID isolation controls. Successful exploitation may enable an attacker… | |
| Analizada | Alta (8.1) | 0.28% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor to perform unauthorized frame injection,… | |
| Analizada | Media (5.4) | 0.09% | — | Arubanetworks Arubaos | 4/3/2026 | 17/6/2026 | A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to… | |
| Analizada | Media (5.3) | 0.36% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the… | |
| Analizada | Alta (7.5) | 0.38% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the… | |
| Analizada | Media (6.5) | 0.36% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system. | |
| Analizada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted… | |
| Analizada | Alta (7.2) | 0.50% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying… | |
| Analizada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged… | |
| Analizada | Alta (7.2) | 0.43% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system. | |
| Analizada | Alta (7.2) | 1.3% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.3% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system. | |
| Analizada | Crítica (9.1) | 0.44% | — | Arubanetworks Arubaos | 13/1/2026 | 17/6/2026 | Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in… | |
| Analizada | Alta (8.8) | 0.89% | — | Arubanetworks Arubaos | 18/11/2025 | 17/6/2026 | A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (7.5) | 0.39% | — | Arubanetworks Arubaos | 18/11/2025 | 17/6/2026 | A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations. | |
| Analizada | Media (6.5) | 0.29% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data. | |
| Analizada | Alta (7.3) | 0.26% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of… | |
| Analizada | Alta (8.8) | 0.66% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system. | |
| Analizada | Alta (8.8) | 0.66% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system. | |
| Analizada | Media (6.8) | 0.30% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional. | |
| Analizada | Alta (7.8) | 0.12% | — | HPE Arubaos-cx | 18/11/2025 | 17/6/2026 | A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges to gain administrator access on the affected system. |