Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.31% | — | Extremenetworks IQ EngineAI | 14/9/2026 | 22/9/2026 | Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send. | |
| Pendiente de análisis | Alta (8.7) | 0.56% | — | Extremenetworks ExtremexosAI | 20/7/2026 | 21/7/2026 | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesystem location and then… | |
| Pendiente de análisis | Alta (8.7) | 0.38% | — | Extremenetworks ExosAI | 20/7/2026 | 21/7/2026 | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization.… | |
| Analizada | Media (6.5) | 0.27% | — | IBM Websphere Extreme Scale | 30/6/2026 | 2/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow… | |
| Analizada | Crítica (10) | 6.1% | — | IBM Websphere Extreme Scale | 30/6/2026 | 2/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an… | |
| Analizada | Crítica (9.9) | 0.51% | — | IBM Websphere Extreme Scale | 30/6/2026 | 3/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who… | |
| Analizada | Alta (8.8) | 0.55% | — | IBM Websphere Extreme Scale | 30/6/2026 | 3/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including… | |
| Pendiente de análisis | Media (6.3) | 0.26% | — | Extreme Platform ONEAIExtremecloud IQAIExtreme XIQAI | 29/5/2026 | 22/7/2026 | A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through… | |
| Analizada | Media (6) | 0.29% | — | Extremenetworks Extremecloud IQ Site Engine | 2/3/2026 | 17/6/2026 | In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface, the application returns the underlying… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themerex Extreme StoreAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from n/a through <= 1.5.10. | |
| Aplazada | Alta (7.1) | 0.21% | — | Extremeidea BidorbuystoreintegratorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extremeidea bidorbuy Store Integrator bidorbuystoreintegrator allows Reflected XSS.This issue affects bidorbuy Store Integrator: from n/a through <= 2.12.0. | |
| Analizada | Alta (8.4) | 0.35% | — | Extremenetworks Fabric Engine (voss) | 7/10/2025 | 17/6/2026 | A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing… | |
| Analizada | Alta (7.6) | 0.34% | — | Extremenetworks Extremeguest Essentials | 1/10/2025 | 17/6/2026 | In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an unauthenticated device to be marked as authenticated and obtain network access.… | |
| Analizada | Alta (7.8) | 0.17% | — | Dell PRO Rugged 13 Ra13250 FirmwareDell PRO Rugged 14 Rb14250 FirmwareDell Latitude 5350 FirmwareDell Latitutde 5450 Firmware+10 | 25/9/2025 | 17/6/2026 | Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code Execution. | |
| Aplazada | Crítica (9.1) | 0.37% | — | Extremeidea Bidorbuy Store IntegratorAI | 28/8/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbuystoreintegrator allows Remote Code Inclusion.This issue affects bidorbuy Store Integrator: from n/a through <= 2.12.0. | |
| Aplazada | Crítica (9.4) | 2.3% | — | Extremez-ip File ServerAI | 13/8/2025 | 16/6/2026 | QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authenticated users can exploit this flaw by submitting crafted sequences to access or write files outside the intended virtual directory. When the "Writable" option is… | |
| Analizada | Media (5.3) | 0.22% | — | Extremenetworks Extremecontrol | 21/7/2025 | 17/6/2026 | In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's browser under… | |
| Analizada | Alta (8.2) | 0.18% | — | Dell Latitude 12 Rugged Extreme 7214 Firmware | 8/7/2025 | 17/6/2026 | Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Media (5.2) | 0.24% | — | Extremenetworks Extremecloud Universal Ztna | 13/6/2025 | 17/6/2026 | In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+257 | 9/4/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Aplazada | Alta (7.6) | 0.25% | — | Extremepacs Extreme XDSAI | 6/3/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data. This issue affects Extreme XDS: before 3933. | |
| Analizada | Crítica (9.8) | 0.58% | — | Extremenetworks Xiq-se | 27/2/2025 | 17/6/2026 | In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation. | |
| Analizada | Alta (8.8) | 0.36% | — | Extremenetworks Xiq-se | 27/2/2025 | 17/6/2026 | In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation. | |
| Analizada | Media (5.3) | 0.30% | — | Extremenetworks Xiq-se | 27/2/2025 | 17/6/2026 | In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met. | |
| Aplazada | Alta (8.8) | 0.40% | — | Extremenetworks IQ EngineAI | 19/2/2025 | 17/6/2026 | Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation of the ah_auth service |