Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 18 respecto a la semana anterior
Críticas / altas1271▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

5320 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.6%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the…
ModificadaAlta (7.2)1.6%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the…
ModificadaAlta (7.2)1.6%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the…
ModificadaAlta (7.2)1.6%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the…
ModificadaCrítica (9.8)1.1%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a…
ModificadaCrítica (9.8)1.1%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a…
ModificadaCrítica (9.8)1.1%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a…
ModificadaCrítica (9.8)1.1%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a…
ModificadaCrítica (9.8)1.1%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a…
ModificadaCrítica (9.8)1.3%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute…
ModificadaCrítica (9.8)1.3%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute…
ModificadaCrítica (9.8)1.7%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute…
ModificadaCrítica (9.8)1.7%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute…
ModificadaCrítica (9.8)1.7%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute…
ModificadaCrítica (9.8)1.7%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute…
ModificadaMedia (6.8)0.92%—Vmware Workspace ONE Content28/2/202317/6/2026
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.
ModificadaMedia (6.1)1.2%💥 ExploitArtisanworkshop Japanized FOR Woocommerce21/2/202317/6/2026
The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaAlta (7.8)0.22%—Citrix Workspace16/2/202317/6/2026
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
ModificadaMedia (5.5)0.26%—Citrix Workspace16/2/202317/6/2026
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
ModificadaMedia (6.5)1.3%—Paloaltonetworks Cortex XsoarFedoraproject Fedora8/2/202317/6/2026
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
ModificadaAlta (7.8)0.29%—Paloaltonetworks Cortex XDR Agent8/2/202317/6/2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.
ModificadaMedia (6.7)0.21%—Paloaltonetworks Cortex XDR Agent8/2/202317/6/2026
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.
ModificadaMedia (5.4)0.58%—Onlyoffice Workspace7/2/202317/6/2026
Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition.
ModificadaAlta (8.4)0.29%—Vmware Workstation3/2/202317/6/2026
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.
ModificadaMedia (4.9)0.79%—Arraynetworks Arrayos AG3/2/202317/6/2026
La interfaz de usuario de Array Networks AG Series y vxAG hasta la versión 9.4.0.470 podría permitir a un atacante remoto utilizar la herramienta gdb para sobrescribir la pila de llamadas de funciones backend después de acceder al sistema con privilegios de administrador. Un exploit exitoso podría aprovechar esta…
Orbitaley — Vulnerabilidades