Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.56% | — | Extremenetworks ExtremexosAI | 20/7/2026 | 21/7/2026 | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesystem location and then… | |
| Aplazada | Sin puntuar | 0.30% | — | Extremenetworks ExtremexosAI | 11/11/2024 | 17/6/2026 | The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this because it is "evaluating support for… | |
| Analizada | Alta (8) | 0.70% | — | Extremenetworks Extremexos | 14/5/2024 | 17/6/2026 | Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges. | |
| Analizada | Alta (8.6) | 0.73% | — | Extremenetworks Extremexos | 3/5/2024 | 17/6/2026 | In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI). | |
| Modificada | Alta (8.1) | 1.0% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values. | |
| Modificada | Media (6.7) | 0.37% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell. | |
| Modificada | Media (6.7) | 0.32% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process. | |
| Modificada | Media (6.7) | 0.27% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell. | |
| Modificada | Alta (7.5) | 1.3% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot. | |
| Modificada | Media (4.4) | 0.34% | — | Extremenetworks Extremexos | 23/10/2017 | 17/6/2026 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files. |