Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
4194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.55% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level. | |
| Modificada | Alta (8.1) | 0.72% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system. | |
| Modificada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.6% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the… | |
| Modificada | Media (6.1) | 0.62% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the… | |
| Analizada | Crítica (9.1) | 0.76% | — | UI Unifi Network Application | 1/7/2023 | 17/6/2026 | A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored. | |
| Modificada | Alta (7.8) | 0.30% | — | ARM NN Android Neural Networks Driver | 29/6/2023 | 17/6/2026 | A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Android-NN-Driver before 23.02. | |
| Modificada | Media (6.8) | 0.92% | — | Ericsson Network Manager | 29/6/2023 | 17/6/2026 | Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected hyperlinks. The attacker would need… | |
| Modificada | Media (4.8) | 0.35% | — | Ericsson Network Manager | 29/6/2023 | 17/6/2026 | Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the… | |
| Modificada | Crítica (9.8) | 0.94% | — | L7-networks InstantqosL7-networks Instantscan | 16/6/2023 | 17/6/2026 | La función de carga de archivos de L7 Networks InstantScan IS-8000 e InstantQoS IQ-8000 no restringen la carga de archivos de tipo peligroso. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para cargar y ejecutar archivos ejecutables arbitrarios para realizar comandos arbitrarios del sistema o… | |
| Modificada | Media (5.4) | 0.37% | — | Paloaltonetworks Pan-os | 14/6/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link. | |
| Modificada | Alta (7.8) | 0.18% | — | Paloaltonetworks Globalprotect | 14/6/2023 | 17/6/2026 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges. | |
| Modificada | Alta (7.5) | 79% | 💥 Exploit | Vmware Vrealize Network Insight | 7/6/2023 | 17/6/2026 | Aria Operations para Networks contiene una vulnerabilidad de divulgación de información. Un agente malintencionado con acceso a la red de VMware Aria Operations para Networks podría realizar un ataque de inyección de comandos que de como resultado la divulgación de información. | |
| Modificada | Alta (8.8) | 82% | 💥 Exploit | Vmware Vrealize Network Insight | 7/6/2023 | 17/6/2026 | Aria Operations para Networks contiene una vulnerabilidad de deserialización autenticada. Un actor malintencionado con acceso de red a VMware Aria Operations para Networks y credenciales de rol de "member" válidas podría realizar un ataque de deserialización que dé como resultado la ejecución remota de código. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Vmware Aria Operations FOR Networks | 7/6/2023 | 17/6/2026 | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | |
| Modificada | Crítica (9.8) | 1.5% | — | Dell Networker | 31/5/2023 | 17/6/2026 | Dell NetWorker v19.6.1.2 contiene una vulnerabilidad de inyección de comandos del sistema operativo en el cliente NetWorker. Un atacante remoto no autenticado podría explotar potencialmente esta vulnerabilidad, llevando a la ejecución de comandos arbitrarios del sistema operativo en el sistema operativo subyacente de… | |
| Modificada | Alta (7.5) | 0.53% | — | Honeywell Onewireless Network Wireless Device Manager Firmware | 30/5/2023 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1 | |
| Modificada | Media (6.8) | 0.29% | — | Honeywell Onewireless Network Wireless Device Manager Firmware | 30/5/2023 | 17/6/2026 | An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in… | |
| Modificada | Media (6.5) | 0.47% | — | Honeywell Onewireless Network Wireless Device Manager Firmware | 30/5/2023 | 17/6/2026 | Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1 | |
| Modificada | Media (4.3) | 0.23% | — | Dell Networker | 30/5/2023 | 17/6/2026 | Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates. | |
| Modificada | Alta (8.8) | 1.5% | — | Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+14 | 22/5/2023 | 17/6/2026 | Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that… | |
| Modificada | Alta (8.8) | 1.1% | — | Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+14 | 22/5/2023 | 17/6/2026 | Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change… | |
| Modificada | Media (6.5) | 0.19% | — | Canon IJ Network Tool | 17/5/2023 | 17/6/2026 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software. | |
| Modificada | Media (6.5) | 0.28% | — | Canon IJ Network Tool | 17/5/2023 | 17/6/2026 | Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software. |