Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)12%—Sonicwall Network Security Manager27/5/202117/6/2026
A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.
ModificadaAlta (7.8)0.36%—Sonicwall Email Security Virtual Appliance13/5/202117/6/2026
SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance remotely only when the device is freshly…
AnalizadaMedia (4.9)52%⚠ Explotación activaSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+720/4/20211/10/2026
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
ModificadaCrítica (9.8)3.7%—Sonicwall Global Management System10/4/202117/6/2026
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
AnalizadaCrítica (9.8)89%⚠ Explotación activa💥 ExploitSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+79/4/202112/8/2026
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
AnalizadaAlta (7.2)17%⚠ Explotación activaSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+79/4/20211/10/2026
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
ModificadaAlta (7.4)18%💥 PoCOpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+2925/3/202117/6/2026
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict…
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaMedia (4.9)0.70%—Sonicwall Sma100 Firmware13/3/202117/6/2026
A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
ModificadaAlta (8.8)1.9%—Sonicwall Sma100 Firmware13/3/202117/6/2026
A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
ModificadaAlta (8.2)0.89%💥 PoCSonicwall Directory Services Connector5/3/202117/6/2026
SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.
ModificadaCrítica (9.8)2.8%—Panasonic Video Insight VMS5/2/202117/6/2026
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request.
AnalizadaCrítica (9.8)40%⚠ Explotación activaSonicwall SMA 100 FirmwareSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 Firmware+24/2/202112/8/2026
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
ModificadaAlta (7.8)1.2%—Panasonic Fpwin PRO26/1/202117/6/2026
FPWIN Pro is vulnerable to an out-of-bounds read vulnerability when a user opens a maliciously crafted project file, which may allow an attacker to remotely execute arbitrary code.
ModificadaMedia (5.3)1.7%💥 ExploitSonicwall Netextender9/1/202117/6/2026
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.
ModificadaAlta (7.2)1.9%—Sonicwall SMA 100 Firmware9/1/202117/6/2026
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.
ModificadaAlta (7.5)1.2%—Panasonic Wv-s2231l Firmware28/12/202017/6/2026
Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&mode=1 in a POST request to the cgi-bin/set_factory URI.
ModificadaMedia (6.8)0.36%—Panasonic Wv-s2231l Firmware28/12/202017/6/2026
Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).
ModificadaAlta (8.6)1.2%—Sonicwall Global VPN Client28/10/202017/6/2026
SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system.
ModificadaAlta (7.8)0.58%—Sonicwall Global VPN Client28/10/202017/6/2026
SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.
ModificadaMedia (5.3)1.6%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS…
ModificadaMedia (6.1)1.2%💥 PoCSonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in the firewall SSLVPN portal. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7,…
ModificadaMedia (6.5)1.3%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.
ModificadaAlta (7.5)1.8%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads to memory addresses leak. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3,…
ModificadaAlta (7.5)1.8%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and…
Orbitaley — Vulnerabilidades