Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
4194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive… | |
| Modificada | Alta (7.2) | 1.1% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system… | |
| Modificada | Alta (7.2) | 1.3% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating… | |
| Modificada | Alta (7.5) | 0.47% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host. | |
| Modificada | Media (6.1) | 0.49% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Alta (8.1) | 0.86% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Media (5.4) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan Orchestrator | 22/8/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a… | |
| Modificada | Alta (8.8) | 58% | 💥 Exploit | Ruijienetworks Rg-ew1200g Firmware | 18/8/2023 | 17/6/2026 | A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (6.1) | 0.46% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. The vulnerability is due to… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These… | |
| Modificada | Media (5.4) | 0.44% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These… | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.7) | 0.11% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 11/8/2023 | 17/6/2026 | La condición de ejecución en el firmware para algunos Intel(R) Ethernet Controllers and Adapters E810 Series anteriores a la versión 1.7.2.4 puede permitir que un usuario autenticado habilite potencialmente la denegación de servicio a través del acceso local. | |
| Modificada | Alta (7.2) | 56% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | Se identificó una inyección de comandos en PRTG 23.2.84.1566 y versiones anteriores en el sensor Dicom C-ECHO donde un usuario autenticado con permisos de escritura podría abusar de la opción de depuración para escribir nuevos archivos que potencialmente podrían ser ejecutados por el sensor EXE/Script. La gravedad de… | |
| Modificada | Alta (7.2) | 14% | 💥 Exploit | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | Se identificó una vulnerabilidad de inyección de comandos en PRTG 23.2.84.1566 y versiones anteriores en el sensor HL7 donde un usuario autenticado con permisos de escritura podría abusar de la opción de depuración para escribir nuevos archivos que potencialmente podrían ser ejecutados por el sensor EXE/Script. La… | |
| Modificada | Alta (8.8) | 0.65% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | Se ha identificado un bypass de token de cross-site request forgery (CSRF) en PRTG 23.2.84.1566 y versiones anteriores que permite a atacantes remotos realizar acciones con los permisos de un usuario víctima, siempre que el usuario víctima tenga una sesión activa y sea inducido a lanzar la petición maliciosa. Esto… | |
| Modificada | Media (4.7) | 0.51% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | Una vulnerabilidad de path traversal fue identificada en los sensores SQL v2 en PRTG 23.2.84.1566 y versiones anteriores donde un usuario autenticado con permisos de escritura podría engañar a los sensores SQL v2 para que se comporten de manera diferente para archivos existentes y archivos no existentes. Esto hacía… | |
| Modificada | Media (4.7) | 0.51% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | Se identificó una vulnerabilidad de path traversal en el sensor WMI Custom en PRTG 23.2.84.1566 y versiones anteriores donde un usuario autenticado con permisos de escritura podía engañar al sensor WMI Custom para que se comportara de forma diferente para archivos existentes y archivos no existentes. Esto hacía… | |
| Modificada | Media (4.7) | 0.51% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | Se identificó una vulnerabilidad de path traversal en el sensor HL7 en PRTG 23.2.84.1566 y versiones anteriores donde un usuario autenticado con permisos de escritura podía engañar al sensor HL7 para que se comportara de forma diferente para archivos existentes y archivos no existentes. Esto hacía posible el path… |