Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
5320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (7.8) | 0.22% | — | Autodesk Infraworks | 12/5/2023 | 17/6/2026 | A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability. | |
| Modificada | Media (6.7) | 0.17% | — | Intel Server Board S1200v3rpl FirmwareIntel Server Board S1200v3rpm FirmwareIntel Server Board S1200v3rpo FirmwareIntel Server Board S1200v3rps Firmware+60 | 12/5/2023 | 17/6/2026 | Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 1.1% | 💥 PoC | Cassianetworks Access Controller | 11/5/2023 | 17/6/2026 | Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users. | |
| Modificada | Media (4.4) | 0.54% | — | Paloaltonetworks Pan-os | 10/5/2023 | 17/6/2026 | A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition. | |
| Modificada | Media (4.8) | 0.43% | — | Paloaltonetworks Pan-os | 10/5/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed. | |
| Modificada | Media (4.8) | 0.24% | — | Arubanetworks ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of… | |
| Modificada | Alta (8.8) | 1.6% | — | Arubanetworks ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (8.8) | 1.6% | — | Arubanetworks ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (8.8) | 1.6% | — | Arubanetworks ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.5) | 0.84% | — | Arubanetworks ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Alta (8.7) | 0.60% | — | Nozominetworks CMCNozominetworks Guardian | 4/5/2023 | 17/6/2026 | Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. | |
| Modificada | Media (4.8) | 0.47% | — | Fullworksplugins Quick Paypal Payments | 2/5/2023 | 17/6/2026 | The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6) | 0.37% | — | Vmware FusionVmware Workstation | 25/4/2023 | 17/6/2026 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | |
| Modificada | Alta (8.2) | 2.0% | — | Vmware FusionVmware Workstation | 25/4/2023 | 17/6/2026 | VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | |
| Modificada | Alta (8.8) | 0.87% | 💥 PoC | Vmware FusionVmware Workstation | 25/4/2023 | 17/6/2026 | VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. | |
| Modificada | Media (5.4) | 0.36% | — | Fullworksplugins Quick Paypal Payments | 25/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. |