Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 12% | — | Sonicwall Network Security Manager | 27/5/2021 | 17/6/2026 | A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions. | |
| Modificada | Alta (7.8) | 0.36% | — | Sonicwall Email Security Virtual Appliance | 13/5/2021 | 17/6/2026 | SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance remotely only when the device is freshly… | |
| Analizada | Media (4.9) | 52% | ⚠ Explotación activa | Sonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+7 | 20/4/2021 | 1/10/2026 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | |
| Modificada | Crítica (9.8) | 3.7% | — | Sonicwall Global Management System | 10/4/2021 | 17/6/2026 | A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root. | |
| Analizada | Crítica (9.8) | 89% | ⚠ Explotación activa💥 Exploit | Sonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+7 | 9/4/2021 | 12/8/2026 | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | |
| Analizada | Alta (7.2) | 17% | ⚠ Explotación activa | Sonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+7 | 9/4/2021 | 1/10/2026 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | |
| Modificada | Alta (7.4) | 18% | 💥 PoC | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Media (4.9) | 0.70% | — | Sonicwall Sma100 Firmware | 13/3/2021 | 17/6/2026 | A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier. | |
| Modificada | Alta (8.8) | 1.9% | — | Sonicwall Sma100 Firmware | 13/3/2021 | 17/6/2026 | A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and earlier. | |
| Modificada | Alta (8.2) | 0.89% | 💥 PoC | Sonicwall Directory Services Connector | 5/3/2021 | 17/6/2026 | SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls. | |
| Modificada | Crítica (9.8) | 2.8% | — | Panasonic Video Insight VMS | 5/2/2021 | 17/6/2026 | Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request. | |
| Analizada | Crítica (9.8) | 40% | ⚠ Explotación activa | Sonicwall SMA 100 FirmwareSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 Firmware+2 | 4/2/2021 | 12/8/2026 | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x. | |
| Modificada | Alta (7.8) | 1.2% | — | Panasonic Fpwin PRO | 26/1/2021 | 17/6/2026 | FPWIN Pro is vulnerable to an out-of-bounds read vulnerability when a user opens a maliciously crafted project file, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Media (5.3) | 1.7% | 💥 Exploit | Sonicwall Netextender | 9/1/2021 | 17/6/2026 | SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier. | |
| Modificada | Alta (7.2) | 1.9% | — | Sonicwall SMA 100 Firmware | 9/1/2021 | 17/6/2026 | A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier. | |
| Modificada | Alta (7.5) | 1.2% | — | Panasonic Wv-s2231l Firmware | 28/12/2020 | 17/6/2026 | Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&mode=1 in a POST request to the cgi-bin/set_factory URI. | |
| Modificada | Media (6.8) | 0.36% | — | Panasonic Wv-s2231l Firmware | 28/12/2020 | 17/6/2026 | Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order). | |
| Modificada | Alta (8.6) | 1.2% | — | Sonicwall Global VPN Client | 28/10/2020 | 17/6/2026 | SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system. | |
| Modificada | Alta (7.8) | 0.58% | — | Sonicwall Global VPN Client | 28/10/2020 | 17/6/2026 | SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability. | |
| Modificada | Media (5.3) | 1.6% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS… | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in the firewall SSLVPN portal. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7,… | |
| Modificada | Media (6.5) | 1.3% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0. | |
| Modificada | Alta (7.5) | 1.8% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service by sending a malicious HTTP request that leads to memory addresses leak. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3,… | |
| Modificada | Alta (7.5) | 1.8% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and… |