Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
415 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | HP ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | HP ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | HP ArubaosHP Instantos | 8/5/2023 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability… | |
| Modificada | Crítica (9.8) | 1.4% | — | Instantdeveloper RD3 | 22/2/2023 | 17/6/2026 | File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.67% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of… | |
| Modificada | Media (4.9) | 0.85% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below;… | |
| Modificada | Media (6.5) | 0.46% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below;… | |
| Modificada | Alta (7.8) | 0.73% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and… | |
| Modificada | Media (5.4) | 0.71% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the… | |
| Modificada | Crítica (9.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and… | |
| Modificada | Crítica (9.8) | 1.4% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability… | |
| Modificada | Crítica (9.8) | 2.1% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability… | |
| Modificada | Crítica (9.8) | 1.9% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability… | |
| Modificada | Crítica (9.8) | 1.9% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 7/10/2022 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability… | |
| Modificada | Crítica (9.8) | 2.0% | — | Arubanetworks ArubaosArubanetworks InstantSiemens Scalance W1750d Firmware | 6/10/2022 | 17/6/2026 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability… | |
| Modificada | Media (6.5) | 0.82% | — | HPE Aruba Instant ON 1930 8G 2sfp FirmwareHPE Aruba Instant ON 1930 8G Class4 POE 2sfp 124w FirmwareHPE Aruba Instant ON 1930 48G Class4 POE 4sfp/sfp+ 370w FirmwareHPE Aruba Instant ON 1930 48G 4sfp/sfp+ Firmware+3 | 12/4/2022 | 17/6/2026 | A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0. | |
| Modificada | Alta (7.5) | 0.95% | — | HPE Aruba Instant ON 1930 8G 2sfp FirmwareHPE Aruba Instant ON 1930 8G Class4 POE 2sfp 124w FirmwareHPE Aruba Instant ON 1930 48G Class4 POE 4sfp/sfp+ 370w FirmwareHPE Aruba Instant ON 1930 48G 4sfp/sfp+ Firmware+3 | 12/4/2022 | 17/6/2026 | A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0. | |
| Modificada | Media (6.5) | 0.92% | — | Jenkins Instant-messaging | 29/3/2022 | 17/6/2026 | Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 18/1/2022 | 17/6/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Analizada | Crítica (9.8) | 97% | 💥 Exploit | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+10 | 20/12/2021 | 17/6/2026 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. | |
| Modificada | Alta (8.2) | 82% | — | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+8 | 20/12/2021 | 17/6/2026 | A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… |