Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to SonicOS crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7…
ModificadaAlta (7.5)1.8%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service and leads to firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7…
ModificadaMedia (6.5)1.1%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-VPN and virtual assist portal, which leads to a firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen…
AnalizadaCrítica (9.8)27%⚠ Explotación activaSonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
ModificadaMedia (6.5)1.1%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a firewall crash. This vulnerability affected SonicOS Gen 6 version 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
ModificadaAlta (7.5)1.8%—Sonicwall SonicosSonicwall Sonicosv12/10/202017/6/2026
A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, which leads to a firewall crash. This vulnerability affected SonicOS Gen 6 version 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
ModificadaMedia (5.3)0.98%—Sonicwall Sma100 FirmwareSonicwall Sonicos30/9/202017/6/2026
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names…
ModificadaAlta (7.8)0.55%—Sonicwall Netextender17/7/202017/6/2026
SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 9.0.815 and earlier.
ModificadaMedia (5.3)1.3%—Sonicwall Sonicos17/7/202017/6/2026
SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier.
ModificadaCrítica (9.8)1.4%—Panasonic Eluga RAY 530 FirmwarePanasonic Eluga RAY 600 FirmwarePanasonic P110 FirmwarePanasonic Eluga Z1 PRO Firmware+220/5/202017/6/2026
Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support."
ModificadaCrítica (9.8)1.7%—Panasonic Video Insight VMS20/5/202017/6/2026
Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.
ModificadaCrítica (9.8)1.5%—Panasonic P99 Firmware19/5/202017/6/2026
Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected products are at "End-of-software-support."
ModificadaAlta (7.5)1.3%—Sonicwall Sma1000 Firmware26/3/202017/6/2026
A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Denial of Service. This vulnerability affected SMA1000 Version 12.1.0-06411 and earlier.
ModificadaCrítica (9.8)89%💥 ExploitSonicwall AnalyzerSonicwall Global Management SystemSonicwall Universal Management ApplianceSonicwall Viewpoint11/2/202016/6/2026
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a…
ModificadaCrítica (9.8)23%💥 ExploitSonicwall AnalyzerSonicwall Global Management SystemSonicwall Universal Management ApplianceSonicwall Viewpoint11/2/202016/6/2026
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain…
ModificadaAlta (7.2)0.92%—Sonicwall SonicosSonicwall Sonicosv31/12/201917/6/2026
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen 5 version 5.9.1.12-4o and earlier, Gen 6 version 6.2.7.4-32n, 6.5.1.4-4n, 6.5.2.3-4n, 6.5.3.3-3n, 6.2.7.10-3n, 6.4.1.0-3n, 6.5.3.3-3n, 6.5.1.9-4n and SonicOSv…
ModificadaCrítica (9.8)1.1%—Sonicwall Global Management System31/12/201917/6/2026
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.
ModificadaCrítica (9.8)5.3%💥 PoCSonicwall Email Security Appliance23/12/201917/6/2026
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
ModificadaCrítica (9.8)1.9%—Sonicwall Email Security Appliance23/12/201917/6/2026
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
ModificadaAlta (7.8)0.46%—Sonicwall SonicosSonicwall Sonicos Sslvpn Nacagent19/12/201917/6/2026
Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.
ModificadaAlta (8.8)1.6%—Sonicwall SMA 100 Firmware19/12/201917/6/2026
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.
ModificadaAlta (8.8)1.5%—Sonicwall SMA 100 Firmware19/12/201917/6/2026
Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
ModificadaMedia (6.5)0.84%—Sonicwall SMA 100 Firmware19/12/201917/6/2026
Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
AnalizadaAlta (7.5)4.0%⚠ Explotación activaSonicwall SMA 100 Firmware19/12/201917/6/2026
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
ModificadaCrítica (9.8)8.8%💥 PoCSonicwall SMA 100 Firmware19/12/201917/6/2026
Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.