Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 5 respecto a la semana anterior
Críticas / altas1274▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
5320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host. | |
| Modificada | Media (6.1) | 0.49% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Alta (8.1) | 0.86% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Alta (8.8) | 58% | 💥 Exploit | Ruijienetworks Rg-ew1200g Firmware | 18/8/2023 | 17/6/2026 | A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (6.5) | 0.59% | — | Thoughtworks Node-worker-threads-pool | 11/8/2023 | 17/6/2026 | Se ha descubierto un problema en StaticPool en node-worker-threads-pool de SUCHMOKUO versión 1.4.3, permite a los atacantes causar una denegación de servicio. | |
| Modificada | Media (5.3) | 0.55% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Se ha detectado una vulnerabilidad de denegación de servicio parcial en la sección Informes, que puede ser explotada por un usuario malicioso ya autenticado que fuerce a guardar un informe con el nombre nulo. La sección de informes estará parcialmente no disponible para todos los intentos posteriores de utilizarla,… | |
| Modificada | Media (6.9) | 0.60% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Un administrador autenticado puede cargar un archivo de configuración SAML con el formato incorrecto, sin que la aplicación compruebe el formato correcto del archivo. Cada solicitud posterior de la aplicación devolverá un error. Toda la aplicación en inutilizable hasta una intervención de la consola. | |
| Modificada | Alta (7.1) | 0.48% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en el control de acceso, debido a que las restricciones que se aplican en las aserciones reales no se aplican en su funcionalidad de depuración. Un usuario autenticado con visibilidad reducida puede obtener información no autorizada a través de la funcionalidad de depuración,… | |
| Analizada | Alta (8.7) | 0.61% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Una vulnerabilidad de inyección blind SQL en Nozomi Networks Guardian y CMC, debida a una validación de entrada incorrecta en el componente alerts_count, permite a un atacante autenticado ejecutar consultas SQL arbitrarias en el DBMS utilizado por la aplicación web. Los usuarios autenticados pueden extraer información… | |
| Modificada | Alta (7.3) | 0.33% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Un atacante autenticado con acceso administrativo al dispositivo puede inyectar código JavaScript malicioso dentro de la definición de una regla de Inteligencia de Amenazas, que posteriormente será ejecutado por otro usuario legítimo que vea los detalles de dicha regla. Un atacante puede ser capaz de realizar acciones… | |
| Modificada | Alta (8.7) | 0.61% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Una vulnerabilidad de inyección blind SQL en Guardian y CMC de Nozomi Networks, debido a una validación de entrada incorrecta en el parámetro de ordenación, permite a un atacante autenticado ejecutar consultas SQL arbitrarias en el DBMS utilizado por la aplicación web. Los usuarios autenticados pueden extraer… | |
| Modificada | Media (5.4) | 0.15% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session. | |
| Modificada | Alta (7.8) | 0.16% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform | 3/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 25/7/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 25/7/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 25/7/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Media (6.1) | 0.43% | — | Assemblysoftware Trialworks | 24/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Assembly Software Trialworks v11.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the asset src parameter. | |
| Modificada | Alta (7.6) | 0.55% | — | Oracle Hyperion Workspace | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Workspace product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks… | |
| Modificada | Media (6.1) | 0.32% | — | Livelyworks Articart | 16/7/2023 | 17/6/2026 | A vulnerability was found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /change-language/de_DE of the component Base64 Encoding Handler. The manipulation of the argument redirectTo leads to open redirect. The attack may be launched… | |
| Modificada | Media (5.4) | 0.36% | — | Livelyworks Articart | 16/7/2023 | 17/6/2026 | A vulnerability has been found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /items/search. The manipulation of the argument search_term leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234229… | |
| Modificada | Crítica (9.8) | 1.1% | — | Extremenetworks IQ Engine | 15/7/2023 | 17/6/2026 | IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit. |