Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
–

4194 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.61%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further privileges on the ClearPass…
ModificadaAlta (7.8)0.18%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance.
ModificadaCrítica (9.8)0.96%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.
ModificadaMedia (5.3)0.44%—Silabs Wireless Smart Ubiquitous Network Linux Border Router Firmware21/3/202317/6/2026
Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network.
AnalizadaCrítica (9.8)68%⚠ Explotación activaArraynetworks Arrayos AG15/3/20235/8/2026
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated…
ModificadaAlta (7.2)1.6%—Arraynetworks Array OS15/3/202317/6/2026
A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer.
ModificadaMedia (6.1)0.63%—Opennetworking Onos14/3/202317/6/2026
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.
ModificadaMedia (5.4)0.45%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due…
ModificadaMedia (6.5)0.55%—Dell EMC Networker1/3/202317/6/2026
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
ModificadaMedia (6.5)0.55%—Dell EMC Networker1/3/202317/6/2026
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
ModificadaMedia (4.8)0.47%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected…
ModificadaMedia (6.5)0.59%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.
ModificadaMedia (4.9)0.71%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
ModificadaMedia (6.5)0.58%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
ModificadaMedia (6.5)0.77%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system.
ModificadaMedia (6.5)0.77%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system.
ModificadaMedia (6.5)0.75%—Arubanetworks Sd-wanArubanetworks Arubaos1/3/202317/6/2026
An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.
ModificadaBaja (2.4)0.44%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account
ModificadaAlta (7.2)1.5%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.5%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.5%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.5%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.5%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.5%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
ModificadaAlta (7.2)1.5%—Arubanetworks ArubaosArubanetworks Sd-wan1/3/202317/6/2026
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.