Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to SonicOS crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7… | |
| Modificada | Alta (7.5) | 1.8% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7… | |
| Modificada | Media (6.5) | 1.1% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-VPN and virtual assist portal, which leads to a firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen… | |
| Analizada | Crítica (9.8) | 27% | ⚠ Explotación activa | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0. | |
| Modificada | Media (6.5) | 1.1% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a firewall crash. This vulnerability affected SonicOS Gen 6 version 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0. | |
| Modificada | Alta (7.5) | 1.8% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a firewall crash. This vulnerability affected SonicOS Gen 6 version 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0. | |
| Modificada | Media (5.3) | 0.98% | — | Sonicwall Sma100 FirmwareSonicwall Sonicos | 30/9/2020 | 17/6/2026 | SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names… | |
| Modificada | Alta (7.8) | 0.55% | — | Sonicwall Netextender | 17/7/2020 | 17/6/2026 | SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 9.0.815 and earlier. | |
| Modificada | Media (5.3) | 1.3% | — | Sonicwall Sonicos | 17/7/2020 | 17/6/2026 | SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier. | |
| Modificada | Crítica (9.8) | 1.4% | — | Panasonic Eluga RAY 530 FirmwarePanasonic Eluga RAY 600 FirmwarePanasonic P110 FirmwarePanasonic Eluga Z1 PRO Firmware+2 | 20/5/2020 | 17/6/2026 | Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support." | |
| Modificada | Crítica (9.8) | 1.7% | — | Panasonic Video Insight VMS | 20/5/2020 | 17/6/2026 | Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.5% | — | Panasonic P99 Firmware | 19/5/2020 | 17/6/2026 | Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected products are at "End-of-software-support." | |
| Modificada | Alta (7.5) | 1.3% | — | Sonicwall Sma1000 Firmware | 26/3/2020 | 17/6/2026 | A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Denial of Service. This vulnerability affected SMA1000 Version 12.1.0-06411 and earlier. | |
| Modificada | Crítica (9.8) | 89% | 💥 Exploit | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall Universal Management ApplianceSonicwall Viewpoint | 11/2/2020 | 16/6/2026 | An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a… | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall Universal Management ApplianceSonicwall Viewpoint | 11/2/2020 | 16/6/2026 | An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain… | |
| Modificada | Alta (7.2) | 0.92% | — | Sonicwall SonicosSonicwall Sonicosv | 31/12/2019 | 17/6/2026 | A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen 5 version 5.9.1.12-4o and earlier, Gen 6 version 6.2.7.4-32n, 6.5.1.4-4n, 6.5.2.3-4n, 6.5.3.3-3n, 6.2.7.10-3n, 6.4.1.0-3n, 6.5.3.3-3n, 6.5.1.9-4n and SonicOSv… | |
| Modificada | Crítica (9.8) | 1.1% | — | Sonicwall Global Management System | 31/12/2019 | 17/6/2026 | A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1. | |
| Modificada | Crítica (9.8) | 5.3% | 💥 PoC | Sonicwall Email Security Appliance | 23/12/2019 | 17/6/2026 | A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier. | |
| Modificada | Crítica (9.8) | 1.9% | — | Sonicwall Email Security Appliance | 23/12/2019 | 17/6/2026 | Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier. | |
| Modificada | Alta (7.8) | 0.46% | — | Sonicwall SonicosSonicwall Sonicos Sslvpn Nacagent | 19/12/2019 | 17/6/2026 | Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution. | |
| Modificada | Alta (8.8) | 1.6% | — | Sonicwall SMA 100 Firmware | 19/12/2019 | 17/6/2026 | Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier. | |
| Modificada | Alta (8.8) | 1.5% | — | Sonicwall SMA 100 Firmware | 19/12/2019 | 17/6/2026 | Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier. | |
| Modificada | Media (6.5) | 0.84% | — | Sonicwall SMA 100 Firmware | 19/12/2019 | 17/6/2026 | Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier. | |
| Analizada | Alta (7.5) | 4.0% | ⚠ Explotación activa | Sonicwall SMA 100 Firmware | 19/12/2019 | 17/6/2026 | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | |
| Modificada | Crítica (9.8) | 8.8% | 💥 PoC | Sonicwall SMA 100 Firmware | 19/12/2019 | 17/6/2026 | Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier. |