Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.42% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure… | |
| Analizada | Media (5.3) | 0.51% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could… | |
| Analizada | Alta (7.1) | 0.26% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance. | |
| Analizada | Alta (7.2) | 0.84% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. | |
| Analizada | Alta (7.2) | 0.55% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise. | |
| Analizada | Alta (7.3) | 0.41% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful… | |
| Analizada | Alta (7.5) | 0.46% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input during the connection process. Successful exploitation could… | |
| Analizada | Alta (7.5) | 0.54% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could… | |
| Analizada | Crítica (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system… | |
| Analizada | Crítica (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 25/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known… | |
| Modificada | Media (4.9) | 0.75% | — | Arubanetworks Analytics AND Location Engine | 4/9/2020 | 17/6/2026 | A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user. |