Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Sega Sonic 4 Episode II Lite9/9/201417/6/2026
The Sonic 4 Episode II LITE (aka com.sega.sonic4ep2lite) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%—Sonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA Em500024/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter.
ModificadaMedia (6.5)75%💥 ExploitSonicwall Scrutinizer16/7/201417/6/2026
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in…
ModificadaMedia (5.5)2.7%—Sonicwall Scrutinizer16/7/201417/6/2026
Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.
ModificadaMedia (4.3)4.8%💥 ExploitSonicwall Email Security Appliance17/4/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the…
ModificadaMedia (4.3)2.4%—Sonicwall NSA 240024/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.
ModificadaMedia (4.3)2.8%—Sonicwall Global Management SystemSonicwall Analyzer14/2/201417/6/2026
Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action.
ModificadaBaja (3.5)4.3%💥 ExploitSonicwall AnalyzerSonicwall Global Management SystemSonicwall UMA E5000 Firmware9/12/201317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2)…
ModificadaBaja (3.3)0.73%—Softbank Wi-fi Spot Configuration SoftwareSoftbank Mobile Wi-fi RouterSoftbank NEC 3G HandsetSoftbank Panasonic 3G Handset+917/6/201316/6/2026
SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the…
ModificadaAlta (7.5)1.1%💥 ExploitSonicwall Aventail SRA EX Virtual ApplianceSonicwall Aventail SRA Ex6000Sonicwall Aventail SRA Ex7000Sonicwall Aventail SRA Ex900012/2/201316/6/2026
SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
ModificadaAlta (7.5)1.1%💥 ExploitDell Sonicwall Viewpoint15/9/201216/6/2026
SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.
ModificadaAlta (7.5)52%💥 ExploitSonicwall Scrutinizer31/7/201216/6/2026
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
ModificadaMedia (4.3)2.5%💥 ExploitSonicwall Scrutinizer31/7/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to d4d/exporters.php, (2) the HTTP Referer header to d4d/exporters.php, or (3) unspecified…
ModificadaAlta (9.4)5.7%💥 ExploitSonicwall Scrutinizer31/7/201216/6/2026
d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request.
ModificadaMedia (5)44%💥 ExploitSonicwall Scrutinizer31/7/201216/6/2026
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.
ModificadaMedia (6.5)67%💥 ExploitSonicwall Scrutinizer30/7/201216/6/2026
SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.
ModificadaAlta (9.3)4.8%—Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control3/11/201016/6/2026
Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
ModificadaMedia (6.8)4.8%—Aladdin Safenet Securewire Access GatewayCisco Adaptive Security ApplianceSonicwall E-class SSL VPNSonicwall SSL VPN+14/12/200916/6/2026
Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that…
ModificadaAlta (10)2.2%—Raidsonic ICY BOX NAS25/8/200916/6/2026
userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (9.3)5.8%💥 ExploitSonicspot Audioactive Player29/5/200916/6/2026
Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist file, as demonstrated by a long .mp3 URL in a .m3u file.
ModificadaMedia (4.3)6.4%💥 ExploitSonicwall Sonicos Enhanced4/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled…
ModificadaMedia (4.3)1.2%—Panasonic BB Hcm511Panasonic BB Hcm515Panasonic BB Hcm527Panasonic BB Hcm531+45/8/200816/6/2026
Cross-site scripting (XSS) vulnerability in the error page feature in Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)1.9%—Codeplex Subsonic21/5/200816/6/2026
SubSonic allows remote attackers to bypass pagesize limits and cause a denial of service (CPU consumption) via a pageindex (aka data page number) of -1.
ModificadaMedia (4.3)1.5%💥 ExploitSonicwall E-mail Security12/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page.
ModificadaBaja (2.1)0.19%—Raidsonic Technology Firmware20/3/200816/6/2026
RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.
Orbitaley — Vulnerabilidades