Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

9809 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.69%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system.
AnalizadaAlta (8.5)0.35%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to…
AnalizadaAlta (8.5)0.36%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host…
AnalizadaAlta (8.6)0.46%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
AnalizadaAlta (8.8)0.63%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating…
AnalizadaAlta (8.8)0.54%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.
AnalizadaAlta (8.8)0.35%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute…
AnalizadaCrítica (9.1)1.5%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.
AnalizadaCrítica (9.8)1.0%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202628/9/2026
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading…
AnalizadaCrítica (9.8)0.61%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the…
AnalizadaCrítica (9.9)0.53%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could…
AnalizadaCrítica (9.9)0.50%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
AnalizadaCrítica (9.9)0.50%—Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System15/9/202625/9/2026
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
AplazadaMedia (6.9)0.20%—MispAICakephpAI15/9/202616/9/2026
Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the normal write verbs POST, PUT, PATCH, and…
AplazadaBaja (2.1)0.37%—Phpgurukul Hostel Management SystemAI15/9/202615/9/2026
A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AplazadaBaja (1.9)0.37%—Phpgurukul Hostel Management SystemAI15/9/202615/9/2026
A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Phpgurukul Daily Expense Tracker SystemAI15/9/202615/9/2026
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public…
AplazadaBaja (2)0.35%—Phpgurukul Daily Expense Tracker SystemAI15/9/202615/9/2026
A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be…
AplazadaMedia (5.5)0.43%—Phpgurukul Daily Expense Tracker SystemAI15/9/202615/9/2026
A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and…
AplazadaMedia (5.4)0.24%—Publishpress AuthorsAI15/9/202615/9/2026
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output…
AplazadaBaja (2.9)0.31%—Phpgurukul Blood Donor Management SystemAI15/9/202615/9/2026
A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword causes cleartext storage in a file or on…
AplazadaMedia (5.5)0.43%—Phpgurukul Blood Donor Management SystemAI15/9/202615/9/2026
A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument fromdate/todate results in sql injection. The attack…
AplazadaMedia (5.5)0.69%—Phpgurukul Blood Donor Management SystemAI15/9/202615/9/2026
A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is…
AplazadaCrítica (9.3)0.64%—MispAICakephpAI14/9/202616/9/2026
The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the…
AplazadaBaja (2.9)0.48%—Phpgurukul Small CRMAI13/9/202616/9/2026
A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is…