Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
433 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Crítica (9.8) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 1/3/2023 | 17/6/2026 | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute… | |
| Modificada | Alta (8.8) | 1.6% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Media (5.5) | 0.59% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition. | |
| Modificada | Media (6.5) | 0.61% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system. | |
| Modificada | Media (5.3) | 0.27% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers. | |
| Modificada | Media (6.5) | 0.25% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller. | |
| Modificada | Alta (7.5) | 0.60% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the impacted controller. | |
| Modificada | Alta (8.1) | 0.83% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system. | |
| Modificada | Alta (8.8) | 0.81% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system. | |
| Modificada | Alta (8.8) | 0.75% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system. | |
| Modificada | Alta (8.8) | 0.76% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system. | |
| Modificada | Alta (7.2) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.7% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.5% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Crítica (9.8) | 1.8% | — | Arubanetworks Sd-wanArubanetworks Arubaos | 12/12/2022 | 17/6/2026 | There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a… | |
| Modificada | Media (5.3) | 0.82% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 10/10/2022 | 17/6/2026 | A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI is accessible on self-managed cloud… | |
| Modificada | Media (6.7) | 0.26% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Sd-wan Vsmart Controller+1 | 30/9/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary commands that are executed as… | |
| Modificada | Alta (7.1) | 0.21% | — | Cisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Sd-wan Vsmart ControllerCisco IOS XE Sd-wan+1 | 30/9/2022 | 17/6/2026 | A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Media (5.3) | 0.92% | — | Cisco Sd-wan | 30/9/2022 | 17/6/2026 | A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using a default static username and password combination. This vulnerability exists because the GUI is… |