Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.19% | — | Watchguard FireboxAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FirePlugins FireBox firebox allows Stored XSS.This issue affects FireBox: from n/a through <= 3.1.0-free. | |
| Modificada | Alta (8.6) | 0.62% | — | Watchguard Fireware | 4/12/2025 | 10/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. | |
| Modificada | Alta (8.6) | 0.69% | — | Watchguard Fireware | 4/12/2025 | 10/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands. | |
| Modificada | Alta (8.6) | 0.44% | — | Watchguard Fireware | 4/12/2025 | 10/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands. | |
| Modificada | Media (4.8) | 0.24% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of… | |
| Aplazada | Media (6.3) | 0.27% | 💥 PoC | Watchguard Mobile VPN With SSL ClientAI | 4/12/2025 | 25/9/2026 | The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed. | |
| Modificada | Alta (7.5) | 0.35% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands. | |
| Modificada | Alta (8.2) | 0.48% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed authentication or management web interface. This vulnerability only affects Firebox systems that have at least one authentication… | |
| Modificada | Media (6.7) | 0.13% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check failure. The on-demand system integrity check in the Fireware Web UI will… | |
| Modificada | Media (4.8) | 0.20% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS. | |
| Modificada | Media (4.8) | 0.20% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. | |
| Modificada | Media (4.8) | 0.20% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. | |
| Modificada | Media (4.8) | 0.20% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. | |
| Modificada | Alta (8.7) | 0.50% | — | Watchguard Fireware | 4/12/2025 | 25/9/2026 | A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. | |
| Aplazada | Crítica (9.3) | 0.68% | — | LongwatchAI | 2/12/2025 | 17/6/2026 | A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence of code signing and execution controls. Exploitation results in SYSTEM-level privileges. | |
| Analizada | Crítica (9.8) | 2.2% | — | Kapilduraphe MCP Watch | 1/12/2025 | 17/6/2026 | MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection vulnerability in the cloneRepo method. The application passes the user-supplied githubUrl argument directly to a system shell via execSync without… | |
| Modificada | Media (4.3) | 0.20% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 21/11/2025 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel… | |
| Modificada | Media (4) | 0.15% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 12/11/2025 | 17/6/2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to bypass ASLR. | |
| Modificada | Alta (7.5) | 0.52% | — | Apple IpadosApple Iphone OSApple VisionosApple Watchos | 4/11/2025 | 17/6/2026 | A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to access sensitive user data. | |
| Modificada | Alta (7.5) | 0.52% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 4/11/2025 | 17/6/2026 | The issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Remote content may be loaded even when the 'Load Remote Images' setting is turned off. | |
| Modificada | Alta (8.1) | 0.49% | — | Apple SafariApple IpadosApple Iphone OSApple Tvos+2 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin. | |
| Modificada | Alta (7.5) | 0.64% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 4/11/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory. | |
| Analizada | Media (4.6) | 0.24% | — | Apple Watchos | 4/11/2025 | 17/6/2026 | An authentication issue was addressed with improved state management. This issue is fixed in watchOS 26.1. An attacker with physical access to a locked Apple Watch may be able to view Live Voicemail. | |
| Modificada | Media (6.5) | 0.61% | — | Apple SafariApple IpadosApple Iphone OSApple Visionos+1 | 4/11/2025 | 15/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Modificada | Media (5.5) | 0.26% | — | Apple IpadosApple Iphone OSApple VisionosApple Watchos | 4/11/2025 | 17/6/2026 | A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. A malicious app may be able to take a screenshot of sensitive information in embedded views. |