Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
–

4194 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.55%—Arubanetworks Arubaos5/7/202317/6/2026
Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
ModificadaAlta (8.1)0.72%—Arubanetworks Arubaos5/7/202317/6/2026
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.
ModificadaAlta (7.2)1.4%—Arubanetworks Arubaos5/7/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.4%—Arubanetworks Arubaos5/7/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.6%—Arubanetworks Arubaos5/7/202317/6/2026
An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the…
ModificadaMedia (6.1)0.62%—Arubanetworks Arubaos5/7/202317/6/2026
A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the…
AnalizadaCrítica (9.1)0.76%—UI Unifi Network Application1/7/202317/6/2026
A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.
ModificadaAlta (7.8)0.30%—ARM NN Android Neural Networks Driver29/6/202317/6/2026
A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Android-NN-Driver before 23.02.
ModificadaMedia (6.8)0.92%—Ericsson Network Manager29/6/202317/6/2026
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected hyperlinks. The attacker would need…
ModificadaMedia (4.8)0.35%—Ericsson Network Manager29/6/202317/6/2026
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the…
ModificadaCrítica (9.8)0.94%—L7-networks InstantqosL7-networks Instantscan16/6/202317/6/2026
La función de carga de archivos de L7 Networks InstantScan IS-8000 e InstantQoS IQ-8000 no restringen la carga de archivos de tipo peligroso. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para cargar y ejecutar archivos ejecutables arbitrarios para realizar comandos arbitrarios del sistema o…
ModificadaMedia (5.4)0.37%—Paloaltonetworks Pan-os14/6/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.
ModificadaAlta (7.8)0.18%—Paloaltonetworks Globalprotect14/6/202317/6/2026
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.
ModificadaAlta (7.5)79%💥 ExploitVmware Vrealize Network Insight7/6/202317/6/2026
Aria Operations para Networks contiene una vulnerabilidad de divulgación de información. Un agente malintencionado con acceso a la red de VMware Aria Operations para Networks podría realizar un ataque de inyección de comandos que de como resultado la divulgación de información.
ModificadaAlta (8.8)82%💥 ExploitVmware Vrealize Network Insight7/6/202317/6/2026
Aria Operations para Networks contiene una vulnerabilidad de deserialización autenticada. Un actor malintencionado con acceso de red a VMware Aria Operations para Networks y credenciales de rol de "member" válidas podría realizar un ataque de deserialización que dé como resultado la ejecución remota de código.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitVmware Aria Operations FOR Networks7/6/202317/6/2026
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
ModificadaCrítica (9.8)1.5%—Dell Networker31/5/202317/6/2026
Dell NetWorker v19.6.1.2 contiene una vulnerabilidad de inyección de comandos del sistema operativo en el cliente NetWorker. Un atacante remoto no autenticado podría explotar potencialmente esta vulnerabilidad, llevando a la ejecución de comandos arbitrarios del sistema operativo en el sistema operativo subyacente de…
ModificadaAlta (7.5)0.53%—Honeywell Onewireless Network Wireless Device Manager Firmware30/5/202317/6/2026
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
ModificadaMedia (6.8)0.29%—Honeywell Onewireless Network Wireless Device Manager Firmware30/5/202317/6/2026
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in…
ModificadaMedia (6.5)0.47%—Honeywell Onewireless Network Wireless Device Manager Firmware30/5/202317/6/2026
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
ModificadaMedia (4.3)0.23%—Dell Networker30/5/202317/6/2026
Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates.
ModificadaAlta (8.8)1.5%—Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+1422/5/202317/6/2026
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that…
ModificadaAlta (8.8)1.1%—Teltonika-networks Rut200 FirmwareTeltonika-networks Rut240 FirmwareTeltonika-networks Rut241 FirmwareTeltonika-networks Rut300 Firmware+1422/5/202317/6/2026
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change…
ModificadaMedia (6.5)0.19%—Canon IJ Network Tool17/5/202317/6/2026
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the communication of the software.
ModificadaMedia (6.5)0.28%—Canon IJ Network Tool17/5/202317/6/2026
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.