Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.7)0.31%—HPE Arubaos-cx1/9/20264/9/2026
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.
AnalizadaMedia (5.3)0.34%—HPE Arubaos-cx1/9/20264/9/2026
Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.
AnalizadaMedia (4.9)0.44%—HPE Arubaos-cx1/9/20265/10/2026
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
AnalizadaAlta (8.3)0.20%—HPE Arubaos-cx1/9/202622/9/2026
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of…
AnalizadaMedia (6.5)0.29%—HPE Arubaos-cx1/9/202622/9/2026
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
AnalizadaAlta (8.8)0.66%—HPE Arubaos-cx1/9/202622/9/2026
Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
AnalizadaAlta (8.8)0.47%—HPE Arubaos-cx1/9/202622/9/2026
An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
AnalizadaAlta (8.8)0.66%—HPE Arubaos-cx1/9/202622/9/2026
An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (8.8)0.80%—HPE Arubaos-cx1/9/202622/9/2026
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a…
AnalizadaCrítica (9.8)0.82%—HPE Arubaos-cx1/9/202622/9/2026
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with…
AnalizadaMedia (6.5)0.27%—HPE Integrated Lights-out 6 Firmware5/8/202610/8/2026
A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
Pendiente de análisisCrítica (9.8)0.80%—HPE Networking Sd-wan OrchestratorAI4/8/20266/8/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target…
Pendiente de análisisCrítica (9.8)0.80%—HPE Networking Sd-wan OrchestratorAI4/8/20266/8/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target…
AnalizadaAlta (7.2)0.87%—HPE Arubaos-cx21/7/202611/8/2026
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
AnalizadaAlta (7.2)0.62%—HPE Arubaos-cx21/7/202611/8/2026
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
AnalizadaAlta (8.8)0.75%—HPE Arubaos-cx21/7/202611/8/2026
A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
Pendiente de análisisMedia (6.5)0.46%—HPE Networking Instant ON 1830AIHPE Networking Instant ON 1930AIHPE Networking Instant ON 1960AI7/7/20269/7/2026
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.
AplazadaBaja (2.1)0.35%—PhpemsAI19/4/202617/6/2026
A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be executed remotely. The exploit is now…
AnalizadaCrítica (9.6)0.32%—HPE Aruba Networking Private 5G Core7/4/202617/6/2026
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled…
AplazadaBaja (2)0.33%—PhpemsAI11/3/202617/6/2026
A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-ask. Performing a manipulation of the argument askcontent results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AnalizadaMedia (6.1)0.29%—HPE Arubaos-cx11/3/202617/6/2026
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
AnalizadaAlta (8.8)1.2%—HPE Arubaos-cx11/3/202622/9/2026
A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (7.2)0.94%—HPE Arubaos-cx11/3/202622/9/2026
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
AnalizadaAlta (8.8)0.56%—HPE Arubaos-cx11/3/202622/9/2026
A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
AnalizadaCrítica (9.8)0.74%💥 PoCHPE Arubaos-cx11/3/202622/9/2026
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
Orbitaley — Vulnerabilidades