Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

197 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.6)0.41%—Arista NG Firewall10/1/202517/6/2026
A user with advanced report application access rights can perform actions for which they are not authorized
AnalizadaAlta (7.1)0.34%—Arista NG Firewall10/1/202517/6/2026
Backup uploads to ETM subject to man-in-the-middle interception
AnalizadaAlta (7.6)0.43%—Arista NG Firewall10/1/202517/6/2026
Specially constructed queries targeting ETM could discover active remote access sessions
AnalizadaMedia (6.8)0.40%—Arista NG Firewall10/1/202517/6/2026
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
AplazadaMedia (4.3)0.48%—Arista EOSAI10/1/202517/6/2026
On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out until snmpd is…
AplazadaMedia (6.5)0.35%—Arista EOSAI10/1/202517/6/2026
On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.
AplazadaMedia (5.8)0.51%—Arista EOSAI10/1/202517/6/2026
On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action and be slow-path…
AnalizadaMedia (6.3)0.50%—Arista NG Firewall20/12/202417/6/2026
Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific flaw…
AnalizadaAlta (7.8)0.16%—Arista NG Firewall20/12/202417/6/2026
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit…
AnalizadaAlta (7.3)1.0%—Arista NG Firewall20/12/202417/6/2026
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaAlta (8.8)1.3%—Arista NG Firewall20/12/202417/6/2026
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExecManagerImpl…
ModificadaAlta (8.1)100%💥 ExploitSonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+491/7/20241/9/2026
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
AplazadaAlta (8.4)0.49%—Arista Wireless Access PointsAI27/6/202417/6/2026
This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit this vulnerability,…
ModificadaCrítica (9.8)0.41%—Typps Calendarista9/6/202417/6/2026
Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.5.
AplazadaMedia (4.3)0.23%—Typps Calendarista Basic EditionAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2.
AplazadaAlta (8.5)0.55%—Typps CalendaristaAI28/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Typps Calendarista.This issue affects Calendarista: from n/a through 15.5.7.
AplazadaAlta (7.1)0.37%—Typps Calendarista-basic-editionAI21/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2.
AnalizadaAlta (8.8)8.8%—Arista NG Firewall4/3/202417/6/2026
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
AnalizadaBaja (3.1)0.34%—Arista Multiaccess4/3/202417/6/2026
On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and some
ModificadaMedia (6.5)0.34%—Arista MOS6/12/202317/6/2026
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config.
ModificadaAlta (7.5)0.67%—Arista EOS29/8/202317/6/2026
On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.
ModificadaMedia (6.5)0.48%—Arista EOS29/8/202317/6/2026
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place.
ModificadaAlta (8.1)0.47%—Arista Cloudvision Portal13/6/202317/6/2026
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision…
ModificadaAlta (7.5)0.62%—Arista EOS5/6/202317/6/2026
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
ModificadaMedia (6.5)0.60%—Arista EOSArista Ceos-labArista CloudeosArista Veos-lab25/4/202317/6/2026
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access…
Orbitaley — Vulnerabilidades