Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 3.4% | ⚠ Explotación activa | Arraynetworks Arrayos AG | 5/12/2025 | 17/6/2026 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. | |
| Modificada | Crítica (9.8) | 1.3% | — | Arraynetworks Arrayos AG | 22/12/2023 | 17/6/2026 | MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected. | |
| Modificada | Alta (7.5) | 0.84% | — | Arraynetworks Arrayos AG | 25/8/2023 | 17/6/2026 | Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations. | |
| Analizada | Crítica (9.8) | 68% | ⚠ Explotación activa | Arraynetworks Arrayos AG | 15/3/2023 | 5/8/2026 | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated… | |
| Modificada | Media (4.9) | 0.79% | — | Arraynetworks Arrayos AG | 3/2/2023 | 17/6/2026 | The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend function call stack after accessing the system with administrator privileges. A successful exploit could leverage this vulnerability in the backend binary file that… | |
| Modificada | Crítica (9.8) | 1.6% | — | Arraynetworks Arrayos AG | 13/10/2022 | 17/6/2026 | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected. |