Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.53% | — | PhpmyfaqAI | 4/9/2026 | 14/9/2026 | phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication. | |
| Aplazada | Media (5.3) | 0.36% | — | PhpmyfaqAI | 4/9/2026 | 8/9/2026 | phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public. | |
| Aplazada | Media (6.9) | 0.49% | — | PhpmyfaqAI | 4/9/2026 | 10/9/2026 | phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications. | |
| Pendiente de análisis | Alta (7.3) | 0.09% | — | HP Support AssistantAI | 3/9/2026 | 8/9/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | |
| Analizada | Media (6.9) | 0.20% | — | Mongodb PHP Driver | 3/9/2026 | 10/9/2026 | An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited… | |
| Aplazada | Media (5.3) | 0.31% | — | Publishpress PermissionsAI | 2/9/2026 | 2/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions. | |
| Analizada | Alta (8.8) | 0.42% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | |
| Analizada | Alta (8.4) | 0.51% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the… | |
| Analizada | Alta (8.2) | 0.24% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information. | |
| Analizada | Crítica (9.8) | 0.51% | — | HPE Arubaos-cx | 1/9/2026 | 10/9/2026 | A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable… | |
| Analizada | Alta (8.1) | 0.46% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. | |
| Analizada | Alta (7.9) | 0.12% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain pre-conditions outside of the attacker’s control… | |
| Analizada | Alta (7.7) | 0.46% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by AOS-CX. | |
| Analizada | Alta (7.6) | 0.29% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of… | |
| Analizada | Alta (7.5) | 0.46% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service. | |
| Analizada | Media (6.5) | 0.29% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying… | |
| Analizada | Alta (7.5) | 0.47% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could… | |
| Analizada | Alta (7.3) | 0.24% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a… | |
| Analizada | Alta (7.3) | 0.19% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges. | |
| Analizada | Alta (7.2) | 1.7% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 1.5% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 0.87% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. | |
| Analizada | Alta (7.1) | 0.31% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services. | |
| Analizada | Alta (8.8) | 0.47% | — | HPE Arubaos-cx | 1/9/2026 | 10/9/2026 | A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility. | |
| Analizada | Media (6.6) | 0.29% | — | HPE Arubaos-cx | 1/9/2026 | 4/9/2026 | A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy. |