Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
–

4194 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.58%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data…
ModificadaMedia (6.5)0.65%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
ModificadaMedia (6.5)0.65%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
ModificadaMedia (6.5)0.65%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
ModificadaAlta (8.8)1.1%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.0%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.0%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.0%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.1%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaAlta (8.8)1.0%—Arubanetworks Edgeconnect Enterprise16/5/202317/6/2026
Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system…
ModificadaMedia (5.3)1.1%💥 PoCCassianetworks Access Controller11/5/202317/6/2026
Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.
ModificadaMedia (4.4)0.54%—Paloaltonetworks Pan-os10/5/202317/6/2026
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
ModificadaMedia (4.8)0.43%—Paloaltonetworks Pan-os10/5/202317/6/2026
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.8)0.24%—Arubanetworks ArubaosHP Instantos8/5/202317/6/2026
A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of…
ModificadaAlta (8.8)1.6%—Arubanetworks ArubaosHP Instantos8/5/202317/6/2026
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (8.8)1.6%—Arubanetworks ArubaosHP Instantos8/5/202317/6/2026
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (8.8)1.6%—Arubanetworks ArubaosHP Instantos8/5/202317/6/2026
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.5)0.84%—Arubanetworks ArubaosHP Instantos8/5/202317/6/2026
An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.
ModificadaAlta (8.7)0.60%—Nozominetworks CMCNozominetworks Guardian4/5/202317/6/2026
Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
ModificadaAlta (7.8)0.33%—Nokia One-network Directory Server25/4/202317/6/2026
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
ModificadaMedia (6.1)0.64%—Thethingsnetwork Lorawan-stack24/4/202317/6/2026
lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an attacker to supply a user controlled redirect upon sign in. This issue may allows malicious actors to phish users, as users assume they were redirected to…
ModificadaMedia (5.3)0.76%—Opennetworking Onos20/4/202317/6/2026
An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of paths installed by intents. An existing intents does not redirect to a new path, even if a new intent that shares the path with higher priority is installed.
ModificadaMedia (5.3)0.57%—Opennetworking Onos20/4/202317/6/2026
An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the INSTALLING state, indicating that its flow rules are installing. Improper handling of such an intent is misleading to a network operator.
ModificadaAlta (7.5)0.88%—Opennetworking Onos20/4/202317/6/2026
An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an invalid flow rule, causing a network loop.