Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.41% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | A user with advanced report application access rights can perform actions for which they are not authorized | |
| Analizada | Alta (7.1) | 0.34% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Backup uploads to ETM subject to man-in-the-middle interception | |
| Analizada | Alta (7.6) | 0.43% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Specially constructed queries targeting ETM could discover active remote access sessions | |
| Analizada | Media (6.8) | 0.40% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access | |
| Aplazada | Media (4.3) | 0.48% | — | Arista EOSAI | 10/1/2025 | 17/6/2026 | On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out until snmpd is… | |
| Aplazada | Media (6.5) | 0.35% | — | Arista EOSAI | 10/1/2025 | 17/6/2026 | On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc. | |
| Aplazada | Media (5.8) | 0.51% | — | Arista EOSAI | 10/1/2025 | 17/6/2026 | On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action and be slow-path… | |
| Analizada | Media (6.3) | 0.50% | — | Arista NG Firewall | 20/12/2024 | 17/6/2026 | Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.8) | 0.16% | — | Arista NG Firewall | 20/12/2024 | 17/6/2026 | Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Analizada | Alta (7.3) | 1.0% | — | Arista NG Firewall | 20/12/2024 | 17/6/2026 | Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Alta (8.8) | 1.3% | — | Arista NG Firewall | 20/12/2024 | 17/6/2026 | Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExecManagerImpl… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Aplazada | Alta (8.4) | 0.49% | — | Arista Wireless Access PointsAI | 27/6/2024 | 17/6/2026 | This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit this vulnerability,… | |
| Modificada | Crítica (9.8) | 0.41% | — | Typps Calendarista | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.5. | |
| Aplazada | Media (4.3) | 0.23% | — | Typps Calendarista Basic EditionAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2. | |
| Aplazada | Alta (8.5) | 0.55% | — | Typps CalendaristaAI | 28/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Typps Calendarista.This issue affects Calendarista: from n/a through 15.5.7. | |
| Aplazada | Alta (7.1) | 0.37% | — | Typps Calendarista-basic-editionAI | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2. | |
| Analizada | Alta (8.8) | 8.8% | — | Arista NG Firewall | 4/3/2024 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. | |
| Analizada | Baja (3.1) | 0.34% | — | Arista Multiaccess | 4/3/2024 | 17/6/2026 | On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and some | |
| Modificada | Media (6.5) | 0.34% | — | Arista MOS | 6/12/2023 | 17/6/2026 | On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config. | |
| Modificada | Alta (7.5) | 0.67% | — | Arista EOS | 29/8/2023 | 17/6/2026 | On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload. | |
| Modificada | Media (6.5) | 0.48% | — | Arista EOS | 29/8/2023 | 17/6/2026 | On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place. | |
| Modificada | Alta (8.1) | 0.47% | — | Arista Cloudvision Portal | 13/6/2023 | 17/6/2026 | On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision… | |
| Modificada | Alta (7.5) | 0.62% | — | Arista EOS | 5/6/2023 | 17/6/2026 | On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart. | |
| Modificada | Media (6.5) | 0.60% | — | Arista EOSArista Ceos-labArista CloudeosArista Veos-lab | 25/4/2023 | 17/6/2026 | On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access… |