Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.83% | — | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access restricted web pages. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |
| Modificada | Crítica (9.8) | 0.31% | — | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |
| Modificada | Alta (8.8) | 41% | — | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges. This issue… | |
| Modificada | Crítica (9.8) | 0.71% | — | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |
| Modificada | Alta (8.8) | 86% | 💥 Exploit | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier… | |
| Modificada | Alta (8.8) | 0.76% | — | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |
| Modificada | Media (6.5) | 25% | — | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |
| Modificada | Alta (7.5) | 0.81% | — | Sonicwall Global Management SystemSonicwall Analytics | 13/7/2023 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |
| Modificada | Media (5.3) | 0.64% | — | Globalscape EFT Server | 22/6/2023 | 17/6/2026 | Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message | |
| Modificada | Alta (7.5) | 0.90% | — | Globalscape EFT Server | 22/6/2023 | 17/6/2026 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service | |
| Modificada | Crítica (9.1) | 0.97% | — | Globalscape EFT Server | 22/6/2023 | 17/6/2026 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited | |
| Modificada | Alta (7.8) | 0.18% | — | Paloaltonetworks Globalprotect | 14/6/2023 | 17/6/2026 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges. | |
| Modificada | Alta (7.3) | 0.56% | — | Hidglobal Safe | 7/6/2023 | 17/6/2026 | The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the… | |
| Modificada | Alta (8.8) | 1.1% | — | Marvalglobal MSM | 7/6/2023 | 17/6/2026 | Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server. | |
| Modificada | Media (5.5) | 0.11% | — | Marvalglobal MSM | 7/6/2023 | 17/6/2026 | Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key. | |
| Modificada | Crítica (9.8) | 0.99% | — | Marvalglobal MSM | 7/6/2023 | 17/6/2026 | Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application. | |
| Modificada | Alta (7.5) | 0.62% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (4.3) | 1.2% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which… | |
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.3) | 0.56% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 3/5/2023 | 17/6/2026 | When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.5) | 0.19% | — | HP OneviewHPE Oneview Global Dashboard | 25/4/2023 | 17/6/2026 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | |
| Modificada | Alta (7.2) | 0.97% | — | Meinbergglobal Lantime Firmware | 24/4/2023 | 17/6/2026 | In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands. | |
| Modificada | Media (5.5) | 0.18% | — | HPE Oneview Global Dashboard | 14/4/2023 | 17/6/2026 | An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials | |
| Modificada | Media (6.3) | 0.11% | — | Paloaltonetworks Globalprotect | 12/4/2023 | 17/6/2026 | A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition. |