Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.69% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system. | |
| Analizada | Alta (8.5) | 0.35% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to… | |
| Analizada | Alta (8.5) | 0.36% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host… | |
| Analizada | Alta (8.6) | 0.46% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations. | |
| Analizada | Alta (8.8) | 0.63% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating… | |
| Analizada | Alta (8.8) | 0.54% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise. | |
| Analizada | Alta (8.8) | 0.35% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute… | |
| Analizada | Crítica (9.1) | 1.5% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise. | |
| Analizada | Crítica (9.8) | 1.0% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading… | |
| Analizada | Crítica (9.8) | 0.61% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the… | |
| Analizada | Crítica (9.9) | 0.53% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could… | |
| Analizada | Crítica (9.9) | 0.50% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise. | |
| Analizada | Crítica (9.9) | 0.50% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise. | |
| Aplazada | Media (6.9) | 0.20% | — | MispAICakephpAI | 15/9/2026 | 16/9/2026 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the normal write verbs POST, PUT, PATCH, and… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Hostel Management SystemAI | 15/9/2026 | 15/9/2026 | A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Baja (1.9) | 0.37% | — | Phpgurukul Hostel Management SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Daily Expense Tracker SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2) | 0.35% | — | Phpgurukul Daily Expense Tracker SystemAI | 15/9/2026 | 15/9/2026 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Daily Expense Tracker SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and… | |
| Aplazada | Media (5.4) | 0.24% | — | Publishpress AuthorsAI | 15/9/2026 | 15/9/2026 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output… | |
| Aplazada | Baja (2.9) | 0.31% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on… | |
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack… | |
| Aplazada | Media (5.5) | 0.69% | — | Phpgurukul Blood Donor Management SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is… | |
| Aplazada | Crítica (9.3) | 0.64% | — | MispAICakephpAI | 14/9/2026 | 16/9/2026 | The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the… | |
| Aplazada | Baja (2.9) | 0.48% | — | Phpgurukul Small CRMAI | 13/9/2026 | 16/9/2026 | A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is… |