Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Sega Sonic 4 Episode II Lite | 9/9/2014 | 17/6/2026 | The Sonic 4 Episode II LITE (aka com.sega.sonic4ep2lite) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA Em5000 | 24/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter. | |
| Modificada | Media (6.5) | 75% | 💥 Exploit | Sonicwall Scrutinizer | 16/7/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in… | |
| Modificada | Media (5.5) | 2.7% | — | Sonicwall Scrutinizer | 16/7/2014 | 17/6/2026 | Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Sonicwall Email Security Appliance | 17/4/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the… | |
| Modificada | Media (4.3) | 2.4% | — | Sonicwall NSA 2400 | 24/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter. | |
| Modificada | Media (4.3) | 2.8% | — | Sonicwall Global Management SystemSonicwall Analyzer | 14/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action. | |
| Modificada | Baja (3.5) | 4.3% | 💥 Exploit | Sonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA E5000 Firmware | 9/12/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2)… | |
| Modificada | Baja (3.3) | 0.73% | — | Softbank Wi-fi Spot Configuration SoftwareSoftbank Mobile Wi-fi RouterSoftbank NEC 3G HandsetSoftbank Panasonic 3G Handset+9 | 17/6/2013 | 16/6/2026 | SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Sonicwall Aventail SRA EX Virtual ApplianceSonicwall Aventail SRA Ex6000Sonicwall Aventail SRA Ex7000Sonicwall Aventail SRA Ex9000 | 12/2/2013 | 16/6/2026 | SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Dell Sonicwall Viewpoint | 15/9/2012 | 16/6/2026 | SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter. | |
| Modificada | Alta (7.5) | 52% | 💥 Exploit | Sonicwall Scrutinizer | 31/7/2012 | 16/6/2026 | The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Sonicwall Scrutinizer | 31/7/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to d4d/exporters.php, (2) the HTTP Referer header to d4d/exporters.php, or (3) unspecified… | |
| Modificada | Alta (9.4) | 5.7% | 💥 Exploit | Sonicwall Scrutinizer | 31/7/2012 | 16/6/2026 | d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request. | |
| Modificada | Media (5) | 44% | 💥 Exploit | Sonicwall Scrutinizer | 31/7/2012 | 16/6/2026 | cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action. | |
| Modificada | Media (6.5) | 67% | 💥 Exploit | Sonicwall Scrutinizer | 30/7/2012 | 16/6/2026 | SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter. | |
| Modificada | Alta (9.3) | 4.8% | — | Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control | 3/11/2010 | 16/6/2026 | Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method. | |
| Modificada | Media (6.8) | 4.8% | — | Aladdin Safenet Securewire Access GatewayCisco Adaptive Security ApplianceSonicwall E-class SSL VPNSonicwall SSL VPN+1 | 4/12/2009 | 16/6/2026 | Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that… | |
| Modificada | Alta (10) | 2.2% | — | Raidsonic ICY BOX NAS | 25/8/2009 | 16/6/2026 | userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (9.3) | 5.8% | 💥 Exploit | Sonicspot Audioactive Player | 29/5/2009 | 16/6/2026 | Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist file, as demonstrated by a long .mp3 URL in a .m3u file. | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Sonicwall Sonicos Enhanced | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled… | |
| Modificada | Media (4.3) | 1.2% | — | Panasonic BB Hcm511Panasonic BB Hcm515Panasonic BB Hcm527Panasonic BB Hcm531+4 | 5/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the error page feature in Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.9% | — | Codeplex Subsonic | 21/5/2008 | 16/6/2026 | SubSonic allows remote attackers to bypass pagesize limits and cause a denial of service (CPU consumption) via a pageindex (aka data page number) of -1. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Sonicwall E-mail Security | 12/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page. | |
| Modificada | Baja (2.1) | 0.19% | — | Raidsonic Technology Firmware | 20/3/2008 | 16/6/2026 | RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key. |