Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 18 respecto a la semana anterior
Críticas / altas1271▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
5320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.6% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the… | |
| Modificada | Alta (7.2) | 1.6% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the… | |
| Modificada | Alta (7.2) | 1.6% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the… | |
| Modificada | Alta (7.2) | 1.6% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the… | |
| Modificada | Crítica (9.8) | 1.1% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a… | |
| Modificada | Crítica (9.8) | 1.1% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a… | |
| Modificada | Crítica (9.8) | 1.1% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a… | |
| Modificada | Crítica (9.8) | 1.1% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a… | |
| Modificada | Crítica (9.8) | 1.1% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a… | |
| Modificada | Crítica (9.8) | 1.3% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.3% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Media (6.8) | 0.92% | — | Vmware Workspace ONE Content | 28/2/2023 | 17/6/2026 | VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 21/2/2023 | 17/6/2026 | The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Alta (7.8) | 0.22% | — | Citrix Workspace | 16/2/2023 | 17/6/2026 | Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | |
| Modificada | Media (5.5) | 0.26% | — | Citrix Workspace | 16/2/2023 | 17/6/2026 | A malicious user can cause log files to be written to a directory that they do not have permission to write to. | |
| Modificada | Media (6.5) | 1.3% | — | Paloaltonetworks Cortex XsoarFedoraproject Fedora | 8/2/2023 | 17/6/2026 | A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. | |
| Modificada | Alta (7.8) | 0.29% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Media (6.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Media (5.4) | 0.58% | — | Onlyoffice Workspace | 7/2/2023 | 17/6/2026 | Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition. | |
| Modificada | Alta (8.4) | 0.29% | — | Vmware Workstation | 3/2/2023 | 17/6/2026 | VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed. | |
| Modificada | Media (4.9) | 0.79% | — | Arraynetworks Arrayos AG | 3/2/2023 | 17/6/2026 | La interfaz de usuario de Array Networks AG Series y vxAG hasta la versión 9.4.0.470 podría permitir a un atacante remoto utilizar la herramienta gdb para sobrescribir la pila de llamadas de funciones backend después de acceder al sistema con privilegios de administrador. Un exploit exitoso podría aprovechar esta… |