Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
4194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.55% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Se ha detectado una vulnerabilidad de denegación de servicio parcial en la sección Informes, que puede ser explotada por un usuario malicioso ya autenticado que fuerce a guardar un informe con el nombre nulo. La sección de informes estará parcialmente no disponible para todos los intentos posteriores de utilizarla,… | |
| Modificada | Media (6.9) | 0.60% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Un administrador autenticado puede cargar un archivo de configuración SAML con el formato incorrecto, sin que la aplicación compruebe el formato correcto del archivo. Cada solicitud posterior de la aplicación devolverá un error. Toda la aplicación en inutilizable hasta una intervención de la consola. | |
| Modificada | Alta (7.1) | 0.48% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en el control de acceso, debido a que las restricciones que se aplican en las aserciones reales no se aplican en su funcionalidad de depuración. Un usuario autenticado con visibilidad reducida puede obtener información no autorizada a través de la funcionalidad de depuración,… | |
| Analizada | Alta (8.7) | 0.61% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Una vulnerabilidad de inyección blind SQL en Nozomi Networks Guardian y CMC, debida a una validación de entrada incorrecta en el componente alerts_count, permite a un atacante autenticado ejecutar consultas SQL arbitrarias en el DBMS utilizado por la aplicación web. Los usuarios autenticados pueden extraer información… | |
| Modificada | Alta (7.3) | 0.33% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Un atacante autenticado con acceso administrativo al dispositivo puede inyectar código JavaScript malicioso dentro de la definición de una regla de Inteligencia de Amenazas, que posteriormente será ejecutado por otro usuario legítimo que vea los detalles de dicha regla. Un atacante puede ser capaz de realizar acciones… | |
| Modificada | Alta (8.7) | 0.61% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | Una vulnerabilidad de inyección blind SQL en Guardian y CMC de Nozomi Networks, debido a una validación de entrada incorrecta en el parámetro de ordenación, permite a un atacante autenticado ejecutar consultas SQL arbitrarias en el DBMS utilizado por la aplicación web. Los usuarios autenticados pueden extraer… | |
| Modificada | Media (5.4) | 0.15% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session. | |
| Modificada | Media (4.3) | 0.45% | — | Jpcert Special Interest Group Network FOR Analysis AND Liaison | 9/8/2023 | 17/6/2026 | Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the attribute information of the poster that is set as"non-disclosure" in the system settings. | |
| Modificada | Media (4.3) | 0.45% | — | Jpcert Special Interest Group Network FOR Analysis AND Liaison | 9/8/2023 | 17/6/2026 | Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization information of the information receiver that is set as "non-disclosure" in the information provision operation. | |
| Modificada | Alta (8.8) | 1.1% | — | Zohocorp Manageengine Network Configuration Manager | 4/8/2023 | 17/6/2026 | Se ha descubierto un problema en Network Configuration Manager 12.6.165 de ManageEngine de Zoho. El WebSocket endpoint permite Cross-site WebSocket hijacking. | |
| Modificada | Alta (7.8) | 0.16% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability… | |
| Modificada | Media (6.1) | 0.85% | — | Golang Networking | 2/8/2023 | 17/6/2026 | Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack. | |
| Modificada | Alta (7.2) | 3.2% | — | Solarwinds Network Configuration Monitor | 26/7/2023 | 17/6/2026 | SolarWinds Network Configuration Manager era susceptible a la vulnerabilidad de Directory Traversal. Esta vulnerabilidad permite a los usuarios con acceso administrativo a SolarWinds Web Console ejecutar comandos arbitrarios. | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 25/7/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 25/7/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosHP Instantos | 25/7/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Media (5.5) | 0.29% | — | Ncia Advisor Network | 18/7/2023 | 17/6/2026 | In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafted JSON file to sanitizeJson and cause an exception. This is related to the U+FFFD Unicode replacement character. A for loop does not consider that a data structure is being modified during loop… | |
| Modificada | Crítica (9.8) | 1.1% | — | Extremenetworks IQ Engine | 15/7/2023 | 17/6/2026 | IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit. | |
| Modificada | Media (4.9) | 0.46% | — | Paloaltonetworks Pan-os | 12/7/2023 | 17/6/2026 | A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Alta (8.8) | 12% | — | Ruijienetworks Bcr810w Firmware | 10/7/2023 | 17/6/2026 | A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Media (4.8) | 0.33% | — | UI Unifi Network Application | 8/7/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page. | |
| Modificada | Alta (7.5) | 0.64% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the controller. | |
| Modificada | Media (6.1) | 0.46% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected… | |
| Modificada | Media (6.5) | 0.55% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level. |