Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.99% | — | Arubanetworks Airwave | 18/11/2025 | 17/6/2026 | A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system. | |
| Aplazada | Alta (7.2) | 0.79% | — | Airwave CLIAI | 10/12/2024 | 17/6/2026 | An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host. | |
| Modificada | Media (6.5) | 0.44% | — | Arubanetworks Airwave | 17/10/2023 | 17/6/2026 | A vulnerability exists which allows an authenticated attacker to access sensitive information on the AirWave Management Platform web-based management interface. Successful exploitation allows the attacker to gain access to some data that could be further exploited to laterally access devices managed and monitored by… | |
| Modificada | Alta (7.2) | 0.85% | — | Arubanetworks AirwaveHP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS. | |
| Modificada | Alta (7.2) | 1.2% | — | Arubanetworks AirwaveHP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users. | |
| Modificada | Alta (8.8) | 0.38% | — | HP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism. | |
| Modificada | Media (6.1) | 0.42% | — | HP Airwave | 5/9/2023 | 17/6/2026 | Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator. | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Airwave | 8/12/2022 | 17/6/2026 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Airwave | 8/12/2022 | 17/6/2026 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at… | |
| Modificada | Alta (8.1) | 0.79% | — | Arubanetworks Airwave | 8/12/2022 | 17/6/2026 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at… | |
| Modificada | Media (4.8) | 0.46% | — | Arubanetworks Airwave | 26/8/2021 | 17/6/2026 | A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Platform that address this security vulnerability. | |
| Modificada | Media (6.1) | 0.75% | — | Arubanetworks Airwave | 29/4/2021 | 17/6/2026 | A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (8.8) | 1.5% | — | Arubanetworks Airwave | 29/4/2021 | 17/6/2026 | A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (8.8) | 1.5% | — | Arubanetworks Airwave | 29/4/2021 | 17/6/2026 | A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (8.1) | 1.2% | — | Arubanetworks Airwave | 29/4/2021 | 17/6/2026 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (8.1) | 1.2% | — | Arubanetworks Airwave | 28/4/2021 | 17/6/2026 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Media (6.5) | 1.3% | — | Arubanetworks Airwave | 28/4/2021 | 17/6/2026 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (7.2) | 1.2% | — | Arubanetworks Airwave | 28/4/2021 | 17/6/2026 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (7.5) | 1.0% | — | Arubanetworks Airwave | 28/4/2021 | 17/6/2026 | A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (8.1) | 1.1% | — | Arubanetworks Airwave | 28/4/2021 | 17/6/2026 | A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (8.8) | 12% | — | Arubanetworks Airwave | 28/4/2021 | 17/6/2026 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Alta (8.1) | 1.3% | — | Arubanetworks Airwave | 28/4/2021 | 17/6/2026 | A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | |
| Modificada | Media (6.3) | 1.3% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit… | |
| Modificada | Media (6.3) | 1.4% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit… | |
| Modificada | Media (6.5) | 1.5% | — | Arubanetworks Airwave | 5/3/2021 | 17/6/2026 | A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management interface of AirWave. A successful exploit could allow an… |