Comodo
Comodo Dome Firewall: vulnerabilidades y CVE
Comodo Dome Firewall tiene 29 vulnerabilidades publicadas, 29 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses29
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-25430 | Media (5.1) | 0.38% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the username parameter. Attackers can… |
| CVE-2019-25429 | Media (5.1) | 0.40% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the openvpn_advanced endpoint. Attackers can inject… |
| CVE-2019-25428 | Media (5.1) | 0.34% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vulnerabilities in the openvpn_users endpoint that allow attackers to inject malicious scripts through POST parameters. Attackers can submit… |
| CVE-2019-25427 | Media (5.1) | 0.41% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the antispyware endpoint. Attackers can send POST… |
| CVE-2019-25426 | Media (5.1) | 0.38% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the dnsmasq endpoint. Attackers can send POST requests… |
| CVE-2019-25425 | Media (5.1) | 0.36% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the VIRUS_ADMIN parameter. Attackers can send POST… |
| CVE-2019-25424 | Media (5.1) | 0.34% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input to the EXCEPTIONSITELIST parameter. Attackers can… |
| CVE-2019-25423 | Media (5.1) | 0.41% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vulnerabilities in the /korugan/proxyconfig endpoint that allow attackers to inject malicious scripts through POST parameters. Attackers can… |
| CVE-2019-25422 | Media (5.3) | 0.35% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the vpnfw endpoint. Attackers can submit POST requests with script payloads in the target… |
| CVE-2019-25421 | Media (5.1) | 0.41% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the policyfw endpoint. Attackers can submit POST requests with JavaScript… |
| CVE-2019-25420 | Media (5.1) | 0.41% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the snat endpoint. Attackers can send POST requests… |
| CVE-2019-25419 | Media (5.3) | 0.37% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests… |
| CVE-2019-25418 | Media (5.1) | 0.36% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the FWADDRESSES parameter. Attackers can send POST… |
| CVE-2019-25417 | Media (5.1) | 0.41% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the protocol parameter. Attackers can send POST… |
| CVE-2019-25416 | Media (5.1) | 0.36% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input through the device parameter. Attackers can send POST… |
| CVE-2019-25415 | Media (5.1) | 0.40% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input to the hotspot_permanent_users endpoint. Attackers can… |
| CVE-2019-25414 | Media (5.1) | 0.40% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the… |
| CVE-2019-25413 | Media (5.1) | 0.40% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the… |
| CVE-2019-25412 | Media (5.1) | 0.34% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input through the NTP_SERVER_LIST parameter. Attackers can… |
| CVE-2019-25411 | Media (5.1) | 0.36% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the GATEWAY_GREEN parameter. Attackers can send POST requests to the… |
| CVE-2019-25410 | Media (5.1) | 0.35% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through the source and destination parameters. Attackers can submit POST requests to… |
| CVE-2019-25409 | Media (5.1) | 0.35% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the destination parameter. Attackers can send POST requests to the… |
| CVE-2019-25408 | Media (5.1) | 0.35% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the netmask_addr parameter. Attackers can send POST… |
| CVE-2019-25407 | Media (5.1) | 0.41% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the backup schedule interface. Attackers can send POST… |
| CVE-2019-25406 | Media (5.1) | 0.35% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the organization parameter. Attackers can send POST requests to the… |
| CVE-2019-25405 | Media (5.3) | 0.31% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the newLicense parameter. Attackers can send POST requests… |
| CVE-2019-25404 | Media (5.1) | 0.31% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input through admin management parameters. Attackers… |
| CVE-2019-25403 | Media (5.1) | 0.30% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the comment parameter. Attackers can inject… |
| CVE-2019-25402 | Media (5.1) | 0.40% | — | 19 feb 2026 | Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the username parameter. Attackers can… |