Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

972 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.22%—Nozominetworks CMCNozominetworks Guardian7/10/202517/6/2026
A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.
AplazadaAlta (8.6)0.31%—Quest DocaveAIQuest PerimeterAIQuest Compliance GuardianAI26/9/202517/6/2026
Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is…
AnalizadaCrítica (9.3)91%⚠ Explotación activa💥 PoCWatchguard Fireware17/9/202510/8/2026
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was…
AplazadaMedia (6.9)0.45%—Watchguard Fireware OSAI15/9/202510/8/2026
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful…
AplazadaMedia (4.8)0.48%—Watchguard FireboxAI15/9/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface…
AplazadaCrítica (9.8)0.66%💥 PoCVoltronicpower ViewpowerAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system…
AplazadaCrítica (10)0.80%💥 PoCVoltronicpower ViewpowerAIVoltronicpower Viewpower PROAIVoltronicpower Powershield NetguardAI22/8/202517/6/2026
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code…
AnalizadaMedia (6.1)0.22%—Fahadmahmood Injection Guard14/8/202517/6/2026
The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
AnalizadaAlta (7.5)0.21%—IBM Guardium Data Protection6/8/202517/6/2026
IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.
AnalizadaAlta (7.8)0.76%—Fastapi-guard Fastapi Guard23/7/202517/6/2026
fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this limit. This type of…
AplazadaMedia (6.5)0.31%—Alertenterprise GuardianAI22/7/202517/6/2026
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the…
AplazadaAlta (7.3)0.38%—Alertenterprise GuardianAI22/7/202517/6/2026
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the following build numbers:…
AplazadaAlta (7.3)0.38%—Alertenterprise GuardianAI22/7/202517/6/2026
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user ID in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the following build numbers:…
AnalizadaBaja (2)0.25%—Phpgurukul Online Security Guards Hiring System18/7/202517/6/2026
A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be initiated remotely. The exploit has…
AplazadaAlta (7)0.13%—Chainguard ApkoAI18/7/202517/6/2026
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.
AnalizadaMedia (5.5)0.15%—Adguard FOR Safari17/7/202517/6/2026
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version 1.11.22.
AnalizadaMedia (6.9)0.45%—Fastapi-guard Fastapi Guard7/7/202517/6/2026
FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. fastapi-guard's penetration attempts detection uses regex to scan incoming requests. However, some of the regex patterns used in detection are extremely inefficient and can cause…
AnalizadaCrítica (9.8)0.50%—Enensys Ipguardv2 Firmware2/7/202517/6/2026
ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
AnalizadaMedia (6.7)0.14%—IBM Guardium Data Protection11/6/202517/6/2026
IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
AplazadaAlta (7.5)1.0%—Nozominetworks GuardianAINozominetworks CMCAI10/6/202517/6/2026
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands. Users with administrative privileges may upload update packages to upgrade the versions of Nozomi Networks Guardian and CMC. While these updates are signed and…
AnalizadaMedia (6.5)0.40%—IBM Security Guardium28/5/202517/6/2026
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
AnalizadaMedia (4.3)0.28%—IBM Security Guardium28/5/202517/6/2026
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.
AnalizadaMedia (5.3)0.35%—IBM Security Guardium28/5/202517/6/2026
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
AplazadaMedia (4.8)0.54%—Watchguard FireboxAI16/5/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management…
AplazadaMedia (4.8)0.45%—Watchguard Fireware OSAI16/5/20258/8/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.
Orbitaley — Vulnerabilidades