Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 27% | 💥 Exploit | Subsonic | 7/6/2017 | 17/6/2026 | XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application… | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal… | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Dell Sonicwall Secure Remote Access Server | 22/2/2017 | 17/6/2026 | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system.… | |
| Modificada | Alta (7.3) | 2.4% | — | Panasonic Video Insight WEB Client | 13/2/2017 | 17/6/2026 | An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution. | |
| Modificada | Media (5.3) | 1.2% | — | Visonic Powerlink2 Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. When a specific URL to an image is accessed, the downloaded image carries with it source code used in the web server (INFORMATION EXPOSURE). | |
| Modificada | Media (6.1) | 1.1% | — | Visonic Powerlink2 Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. User controlled input is not neutralized prior to being placed in web page output (CROSS-SITE SCRIPTING). | |
| Modificada | Media (4.2) | 0.54% | — | Panasonic Fpwin PRO | 12/5/2016 | 17/6/2026 | Heap-based buffer overflow in Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service (application crash) via unspecified vectors. | |
| Modificada | Media (5.5) | 0.91% | — | Panasonic Fpwin PRO | 12/5/2016 | 17/6/2026 | Panasonic FPWIN Pro 5.x through 7.x before 7.130 accesses an uninitialized pointer, which allows local users to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Media (4.2) | 0.58% | — | Panasonic Fpwin PRO | 12/5/2016 | 17/6/2026 | Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion." | |
| Modificada | Media (4.2) | 0.29% | — | Panasonic Fpwin PRO | 12/5/2016 | 17/6/2026 | Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by triggering a crafted index value, as demonstrated by an integer overflow. | |
| Modificada | Crítica (9.8) | 6.4% | — | Sonicwall UMA Em5000 FirmwareSonicwall AnalyzerSonicwall Global Management System | 17/2/2016 | 17/6/2026 | The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data. | |
| Modificada | Crítica (9.9) | 4.7% | — | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA Em5000 Firmware | 17/2/2016 | 17/6/2026 | The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vectors related to configuration input. | |
| Modificada | Media (5) | 2.9% | — | Dell Sonicwall Totalsecure TZ 100 Firmware | 6/11/2015 | 17/6/2026 | Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet. | |
| Modificada | Media (6.9) | 2.1% | — | Sonicwall Netextender | 26/8/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder. | |
| Modificada | Alta (7.5) | 6.4% | — | Panasonic Security API Activex SDK | 6/7/2015 | 17/6/2026 | Stack-based buffer overflow in the Ipropsapi.ipropsapiCtrl.1 ActiveX control in ipropsapivideo in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allows remote attackers to execute arbitrary code via a long string to the MulticastAddr method. | |
| Modificada | Media (6.8) | 5.6% | — | Panasonic Security API Activex SDK | 6/7/2015 | 17/6/2026 | Multiple stack-based buffer overflows in Ipropsapi in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allow remote attackers to execute arbitrary code via a long string in the (1) FilePassword property or to the (2) GetStringInfo method. | |
| Modificada | Alta (9) | 2.7% | — | Sonicwall UMA Em5000 FirmwareSonicwall AnalyzerSonicwall Global Management System | 20/5/2015 | 17/6/2026 | The GMS ViewPoint (GMSVP) web application in Dell Sonicwall GMS, Analyzer, and UMA EM5000 before 7.2 SP4 allows remote authenticated users to execute arbitrary commands via vectors related to configuration. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | Sonicwall Remote Access Firmware | 1/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to… | |
| Modificada | Media (4.3) | 2.3% | — | Sonicwall Sonicos | 29/4/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter. | |
| Modificada | Media (4.3) | 0.73% | — | Panasonic Arbitrator Back-end Server MK 3.0 VPU FirmwarePanasonic Arbitrator Back-end Server MK 3.0 VPUPanasonic Arbitrator Back-end Server MK 2.0 VPU FirmwarePanasonic Arbitrator Back-end Server MK 2.0 VPU | 15/1/2015 | 17/6/2026 | Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU before 9.3.1 build 4.08.003.0, when USB Wi-Fi or Direct LAN is enabled, and MK 3.0 VPU before 9.3.1 build 5.06.000.0, when Embedded Wi-Fi or Direct LAN is enabled, does not use encryption, which allows remote attackers to obtain sensitive information by sniffing… | |
| Modificada | Alta (9) | 24% | 💥 Exploit | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA Em5000 | 25/11/2014 | 17/6/2026 | The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.8) | 3.7% | — | Panasonic Network Camera Recorder Firmware | 17/10/2014 | 17/6/2026 | The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address. | |
| Modificada | Media (6.8) | 2.6% | — | Panasonic Network Camera View | 17/10/2014 | 17/6/2026 | Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which triggers an invalid pointer dereference, related to "the ability to nullify an arbitrary address in memory." | |
| Modificada | Media (5.4) | 0.27% | — | Sega Sonic CD Lite | 9/9/2014 | 17/6/2026 | The Sonic CD Lite (aka com.soa.sega.soniccdlite) application 1.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |