Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.83%—Sonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access restricted web pages. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
ModificadaCrítica (9.8)0.31%—Sonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
ModificadaAlta (8.8)41%—Sonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges. This issue…
ModificadaCrítica (9.8)0.71%—Sonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
ModificadaAlta (8.8)86%💥 ExploitSonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier…
ModificadaAlta (8.8)0.76%—Sonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
ModificadaMedia (6.5)25%—Sonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
ModificadaCrítica (9.8)50%💥 ExploitSonicwall AnalyticsSonicwall Global Management System13/7/202317/6/2026
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
ModificadaAlta (7.5)0.81%—Sonicwall Global Management SystemSonicwall Analytics13/7/202317/6/2026
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
ModificadaMedia (5.3)0.64%—Globalscape EFT Server22/6/202317/6/2026
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message
ModificadaAlta (7.5)0.90%—Globalscape EFT Server22/6/202317/6/2026
Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service
ModificadaCrítica (9.1)0.97%—Globalscape EFT Server22/6/202317/6/2026
Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited
ModificadaAlta (7.8)0.18%—Paloaltonetworks Globalprotect14/6/202317/6/2026
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.
ModificadaAlta (7.3)0.56%—Hidglobal Safe7/6/202317/6/2026
The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the…
ModificadaAlta (8.8)1.1%—Marvalglobal MSM7/6/202317/6/2026
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.
ModificadaMedia (5.5)0.11%—Marvalglobal MSM7/6/202317/6/2026
Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.
ModificadaCrítica (9.8)0.99%—Marvalglobal MSM7/6/202317/6/2026
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.
ModificadaAlta (7.5)0.62%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (4.3)1.2%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which…
ModificadaMedia (6.1)0.39%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (5.3)0.56%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+163/5/202317/6/2026
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (5.5)0.19%—HP OneviewHPE Oneview Global Dashboard25/4/202317/6/2026
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
ModificadaAlta (7.2)0.97%—Meinbergglobal Lantime Firmware24/4/202317/6/2026
In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.
ModificadaMedia (5.5)0.18%—HPE Oneview Global Dashboard14/4/202317/6/2026
An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials
ModificadaMedia (6.3)0.11%—Paloaltonetworks Globalprotect12/4/202317/6/2026
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
Orbitaley — Vulnerabilidades