Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

433 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.50%—Cisco IOS XE Sd-wan15/11/202417/6/2026
This vulnerability exists because Cisco IOS Software and Cisco IOS XE Software do not support extended IPv4 ACLs for SNMP, but they do allow administrators to configure extended named IPv4 ACLs that are attached to the SNMP server configuration without a warning message. This can result in no ACL being applied to the…
AplazadaMedia (6.1)0.22%—Cisco Sd-wan Vedge SoftwareAI25/9/202417/6/2026
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a…
AnalizadaMedia (5.4)0.33%—Cisco Catalyst Sd-wan Manager25/9/202417/6/2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does…
AnalizadaAlta (8.6)0.66%—Cisco IOS XECisco IOS XE Sd-wan25/9/202417/6/2026
A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because UTD…
ModificadaAlta (8.8)0.91%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
AplazadaAlta (7.2)0.75%—HPE Aruba Networking Edgeconnect Sd-wanAI24/7/202417/6/2026
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the…
ModificadaMedia (6.1)0.30%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the…
ModificadaCrítica (9)0.54%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a…
ModificadaAlta (8.8)0.78%—Arubanetworks Edgeconnect Sd-wan Orchestrator24/7/202417/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating…
AnalizadaCrítica (9.8)15%—Arubanetworks Sd-wanArubanetworks Arubaos1/5/202422/9/2026
There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability…
AplazadaAlta (7.1)0.39%—Vmware Sd-wan OrchestratorAI2/4/202417/6/2026
VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
AplazadaMedia (4.8)0.21%—Vmware Sd-wan EdgeAI2/4/202417/6/2026
VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the…
AplazadaAlta (7.4)0.41%—Vmware Sd-wan EdgeAI2/4/202417/6/2026
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router.
AnalizadaMedia (5.3)0.37%—Citrix Sd-wan 1000 FirmwareCitrix Sd-wan 110 FirmwareCitrix Sd-wan 1100 FirmwareCitrix Sd-wan 2000 Firmware+812/3/202417/6/2026
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
ModificadaMedia (6.5)0.53%—Cisco Catalyst Sd-wan Manager18/10/202317/6/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to…
ModificadaAlta (7.5)1.0%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage27/9/202317/6/2026
A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to function, and web UI access is not affected. This…
ModificadaAlta (8.8)0.83%—Cisco Sd-wan Manager27/9/202317/6/2026
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled.…
ModificadaMedia (5.5)0.17%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage27/9/202317/6/2026
A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacker to bypass authorization and allow the attacker to roll back the configuration on vManage controllers and edge router device. This vulnerability is due to improper access control…
ModificadaCrítica (9.8)1.1%—Cisco Catalyst Sd-wan Manager27/9/202317/6/2026
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper authentication checks for SAML APIs. An attacker…
ModificadaMedia (5.4)0.44%—Cisco Sd-wan Vmanage27/9/202317/6/2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to inject HTML content. This vulnerability is due to improper validation of user-supplied data in element fields. An attacker could exploit this…
ModificadaAlta (7.5)0.79%—Cisco Sd-wan27/9/202317/6/2026
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static…
ModificadaMedia (5.3)0.56%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN…
ModificadaMedia (6.1)0.48%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
ModificadaMedia (6.5)0.77%—Arubanetworks Edgeconnect Sd-wan Orchestrator22/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive…
Orbitaley — Vulnerabilidades