Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
174 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 1.2% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Media (6.3) | 1.2% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.2) | 3.0% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.2) | 3.0% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Media (6.5) | 1.2% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote denial of service (DoS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Media (4.3) | 0.98% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.2) | 1.3% | — | Arubanetworks Clearpass Policy Manager | 8/7/2021 | 17/6/2026 | A remote insecure deserialization vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.8) | 0.25% | — | Arubanetworks Clearpass Policy Manager | 28/4/2021 | 17/6/2026 | A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.2) | 2.5% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful… | |
| Modificada | Alta (7.2) | 2.5% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful… | |
| Modificada | Alta (7.8) | 0.31% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platform to elevate their privileges. A successful exploit could allow… | |
| Modificada | Media (5.3) | 0.28% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users to cause a buffer overflow condition. A successful exploit could allow a local attacker to… | |
| Modificada | Media (6.5) | 1.3% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the… | |
| Modificada | Alta (7.2) | 2.5% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful… | |
| Modificada | Alta (7.2) | 2.5% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful… | |
| Modificada | Media (6.1) | 0.83% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the guest portal interface of ClearPass could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a… | |
| Modificada | Alta (7.2) | 2.5% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an… | |
| Modificada | Media (6.1) | 0.90% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface of ClearPass could allow an unauthenticated remote attacker to conduct a stored cross-site… | |
| Modificada | Media (6.5) | 1.2% | — | Arubanetworks Clearpass Policy Manager | 23/2/2021 | 17/6/2026 | A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the… | |
| Modificada | Alta (7.2) | 3.3% | — | Arubanetworks Clearpass Policy Manager | 3/6/2020 | 17/6/2026 | The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in… | |
| Modificada | Alta (7.2) | 3.3% | — | Arubanetworks Clearpass Policy Manager | 3/6/2020 | 17/6/2026 | The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in… | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Arubanetworks Clearpass Policy Manager | 3/6/2020 | 17/6/2026 | The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and… | |
| Modificada | Alta (7.2) | 0.94% | — | Arubanetworks Clearpass Policy Manager | 7/12/2018 | 17/6/2026 | Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view,… | |
| Modificada | Alta (7.2) | 1.3% | — | Arubanetworks Clearpass Policy Manager | 7/12/2018 | 17/6/2026 | A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of ClearPass could allow an attacker to compromise the entire cluster through a specially crafted API call. Network access to the administrative web interface is required to… |