Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

972 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.22%—IBM Security Guardium19/12/202417/6/2026
IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AnalizadaBaja (3.7)0.25%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…
AnalizadaAlta (7.5)0.26%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
AnalizadaMedia (4.3)0.47%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
AnalizadaMedia (4.4)0.19%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
AnalizadaMedia (4.4)0.35%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
AplazadaMedia (4.3)0.41%—Fahadmahmood Injection GuardAI13/12/202417/6/2026
Missing Authorization vulnerability in Fahad Mahmood Injection Guard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Injection Guard: from n/a through 1.2.1.
AplazadaMedia (4.3)0.14%—Digitalguardian Removable Media EncryptionAI15/11/202417/6/2026
A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.
AplazadaAlta (8.5)0.19%—Watchguard EpdrAIPanda Ad360AIPanda DomeAI8/11/20248/8/2026
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.
AnalizadaMedia (6.1)0.30%—Westguardsolutions WS Form6/11/202417/6/2026
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.244. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (5.3)0.15%—Oneidentity Safeguard FOR Privileged SessionsAI24/10/202417/6/2026
An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information.
AnalizadaAlta (8.7)0.55%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Controllogix 5580 Process FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 Firmware+414/10/202417/6/2026
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To…
AplazadaMedia (4.9)0.80%—Adguard HomeAI8/10/202417/6/2026
An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file into a readable directory.
AnalizadaAlta (8.7)0.52%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Compactlogix 5480 FirmwareRockwellautomation Controllogix 5580 Firmware+28/10/202417/6/2026
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to…
AplazadaAlta (7.1)0.32%—Mark Westguard WS Form LiteAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Westguard WS Form LITE ws-form allows Stored XSS.This issue affects WS Form LITE: from n/a through <= 1.9.238.
ModificadaAlta (8.7)0.64%—Watchguard Single Sign-on Client25/9/20248/8/2026
Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing…
ModificadaCrítica (9.3)0.58%—Watchguard Authentication Gateway25/9/20248/8/2026
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and…
ModificadaCrítica (9.3)1.2%💥 PoCWatchguard Authentication GatewayWatchguard Single Sign-on Client25/9/20248/8/2026
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an…
AplazadaAlta (7.8)0.38%—Guardrailsai GuardrailsAI18/9/202417/6/2026
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the…
AnalizadaAlta (8.7)0.56%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 3 FirmwareRockwellautomation Compactlogix 5480 Firmware+312/9/202417/6/2026
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.
ModificadaMedia (5.8)0.22%—Nozominetworks CMCNozominetworks Guardian11/9/202417/6/2026
An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they might be able to make limited changes to the…
AnalizadaAlta (8.8)0.76%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
ModificadaMedia (5.7)0.41%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which…
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+2610/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.