Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

293.976 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.7)0.09%—Aruba Clearpass ClientAI6/10/20267/10/2026
A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges on the affected system, if certain conditions outside of the attacker's control are met.
Pendiente de análisisMedia (6.1)0.09%—HPE Clearpass Policy ManagerAI6/10/20267/10/2026
A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to interrupt the normal operation of the agent service.
Pendiente de análisisAlta (7.2)0.30%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands.
Pendiente de análisisAlta (7.2)0.52%—HPE Clearpass Policy ManagerAI6/10/20267/10/2026
Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating…
Pendiente de análisisAlta (7.3)0.24%—Arista Clearpass Policy ManagerAI6/10/20267/10/2026
An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.
Pendiente de análisisAlta (7.8)0.11%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service.
Pendiente de análisisAlta (7.8)0.11%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.
Pendiente de análisisAlta (7.8)0.11%—Aruba Clearpass Policy Manager OnguardAI6/10/20267/10/2026
A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.
Pendiente de análisisCrítica (9.8)0.36%—Arista Clearpass Policy ManagerAI6/10/20267/10/2026
An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.
Pendiente de análisisAlta (8.8)0.74%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.
Pendiente de análisisAlta (8.8)1.1%—Arista Clearpass Policy ManagerAI6/10/20267/10/2026
A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.
Pendiente de análisisCrítica (9.8)0.64%—HPE Clearpass Policy ManagerAI6/10/20267/10/2026
A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.
Pendiente de análisisAlta (8.8)0.55%—Arista Clearpass Policy ManagerAI6/10/20267/10/2026
An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.
Pendiente de análisisAlta (8.8)0.29%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a…
Pendiente de análisisCrítica (9.9)0.34%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
Pendiente de análisisAlta (8.8)0.30%—HPE Clearpass Policy ManagerAI6/10/20267/10/2026
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive…
Pendiente de análisisCrítica (9.8)0.47%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.
Pendiente de análisisCrítica (9.1)0.30%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
Pendiente de análisisCrítica (9.8)0.37%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
Pendiente de análisisCrítica (9.8)0.53%—HPE Clearpass Policy ManagerAI6/10/20267/10/2026
A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.
Pendiente de análisisCrítica (9.8)0.47%—HPE Clearpass Policy ManagerAI6/10/20267/10/2026
Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.
Pendiente de análisisCrítica (9.8)0.53%—Aruba Clearpass Policy ManagerAI6/10/20267/10/2026
A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.
Pendiente de análisisCrítica (9.8)0.53%—HPE Clearpass Policy ManagerAI6/10/20267/10/2026
Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.
Pendiente de análisisMedia (5.5)0.23%—Kubernetes Cri-oAI6/10/20267/10/2026
A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the…
Pendiente de análisisAlta (8.9)0.40%—Peteroupc CborAI6/10/20267/10/2026
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an…