Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3063▲ 557 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

233 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (2.7)0.23%—HPE Networking Instant ONAI29/9/202630/9/2026
A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers…
Pendiente de análisisBaja (3)0.10%—HPE Networking Instant ONAI29/9/202630/9/2026
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Pendiente de análisisBaja (3.3)0.09%—HPE Networking Instant ONAI29/9/202630/9/2026
A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
Pendiente de análisisMedia (4.1)0.09%—HPE Networking Instant ONAI29/9/202630/9/2026
A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported…
Pendiente de análisisMedia (4.8)0.29%—HPE Networking Instant ONAI29/9/202630/9/2026
A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information…
Pendiente de análisisMedia (4.9)0.31%—HPE Networking Instant ONAI29/9/202630/9/2026
A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes…
Pendiente de análisisMedia (6.4)0.10%—HPE Networking Instant ONAI29/9/20261/10/2026
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
Pendiente de análisisMedia (6.5)0.32%—HPE Networking Instant ONAI29/9/202630/9/2026
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected…
Pendiente de análisisMedia (6.6)0.42%—HPE Networking Instant ON APSAI29/9/20261/10/2026
A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the…
Pendiente de análisisAlta (7.2)0.55%—HPE Networking Instant ON Access PointAI29/9/20261/10/2026
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating…
Pendiente de análisisAlta (7.2)0.98%—HPE Networking Instant ONAI29/9/20261/10/2026
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying…
Pendiente de análisisAlta (8.1)0.36%—HPE Networking Instant ONAI29/9/20261/10/2026
An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to…
Pendiente de análisisCrítica (9.6)0.31%—HPE Networking Instant ON APSAI29/9/20261/10/2026
Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Pendiente de análisisCrítica (9.8)0.54%—HPE Networking Instant ONAI29/9/20261/10/2026
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
Pendiente de análisisCrítica (9.8)0.56%—HPE Networking Instant ONAI29/9/202630/9/2026
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Pendiente de análisisCrítica (9.8)0.80%—HPE Networking Sd-wan OrchestratorAI4/8/20266/8/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target…
Pendiente de análisisCrítica (9.8)0.80%—HPE Networking Sd-wan OrchestratorAI4/8/20266/8/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target…
AnalizadaCrítica (9.6)0.19%—Qualcomm Sm7550p FirmwareQualcomm Sm7635p FirmwareQualcomm Sm7675 FirmwareQualcomm Sm7675p Firmware+1974/8/20266/8/2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
AplazadaAlta (7.2)0.92%—Hikvision Networking ProductsAI31/7/202628/8/2026
Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Pendiente de análisisMedia (6.5)0.46%—HPE Networking Instant ON 1830AIHPE Networking Instant ON 1930AIHPE Networking Instant ON 1960AI7/7/20269/7/2026
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.
AnalizadaAlta (8.8)0.11%—Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+1246/7/20267/7/2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
AnalizadaAlta (8.2)0.07%—Qualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2421/6/202622/7/2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
AnalizadaMedia (5.5)0.09%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+1831/6/202622/7/2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
Pendiente de análisisMedia (4.3)0.18%—Gnome Glib-networkingAIGnutlsAI28/5/202621/7/2026
A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships,…