Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
972 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.52% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS. | |
| Modificada | Alta (8.1) | 0.52% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS. | |
| Modificada | Alta (8.1) | 0.52% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS. | |
| Modificada | Alta (8.8) | 0.56% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. | |
| Analizada | Alta (8.8) | 0.56% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices. | |
| Analizada | Alta (8.8) | 0.74% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices. | |
| Analizada | Alta (8.8) | 0.74% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices. | |
| Analizada | Media (5.3) | 0.48% | — | Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+32 | 10/9/2024 | 17/6/2026 | An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers. | |
| Aplazada | Crítica (9.8) | 51% | 💥 Exploit | Oneidentity Safeguard FOR Privileged PasswordsAI | 30/8/2024 | 17/6/2026 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2. | |
| Analizada | Alta (8.7) | 0.52% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 Firmware+2 | 14/8/2024 | 17/6/2026 | CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller. | |
| Analizada | Alta (8.7) | 0.50% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 Firmware+2 | 14/8/2024 | 17/6/2026 | CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller. | |
| Analizada | Alta (8.7) | 0.58% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 Firmware | 14/8/2024 | 17/6/2026 | CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service. | |
| Modificada | Alta (7.5) | 0.66% | — | Ip-guard | 22/7/2024 | 17/6/2026 | IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter. | |
| Aplazada | Media (5.9) | 0.41% | — | Guardrailsai GuardrailsAI | 21/7/2024 | 17/6/2026 | RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL documents from external sources are vulnerable to XXE, which may cause leakage of internal file data via the SYSTEM entity. | |
| Modificada | Alta (8.6) | 1.1% | — | Watchguard Fireware | 9/7/2024 | 7/8/2026 | A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3. | |
| Modificada | Alta (8.6) | 0.34% | — | Watchguard Mobile VPN With SSL | 9/7/2024 | 7/8/2026 | A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged. | |
| Aplazada | Media (5.3) | 1.2% | 💥 Exploit | JP Datasolutions Siteguard WP PluginAI | 19/6/2024 | 17/6/2026 | SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. However, SiteGuard WP Plugin versions prior to 1.7.7 missed to implement a measure to avoid redirection from wp-register.php. As a result, the customized path… | |
| Analizada | Alta (8.3) | 0.31% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation 1756-en4 FirmwareRockwellautomation Compactlogix 5380 Firmware+2 | 14/6/2024 | 17/6/2026 | Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised. | |
| Aplazada | Alta (8.8) | 0.21% | — | AdguardhomeAI | 13/6/2024 | 17/6/2026 | An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary. | |
| Modificada | Alta (8.8) | 0.49% | — | Westguardsolutions WS Form | 7/6/2024 | 17/6/2026 | The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable… | |
| Aplazada | Alta (7.5) | 0.44% | — | Chainguard ApkoAI | 3/6/2024 | 17/6/2026 | apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5. | |
| Analizada | Alta (8.6) | 100% | ⚠ Explotación activa💥 Exploit | Checkpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security | 28/5/2024 | 5/8/2026 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | |
| Analizada | Media (5.4) | 0.25% | — | IBM Security Guardium | 24/5/2024 | 17/6/2026 | IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271525. | |
| Aplazada | Alta (7.2) | 0.21% | — | Intel Bios Guard FirmwareAI | 16/5/2024 | 17/6/2026 | Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.2) | 0.19% | — | Intel Bios Guard FirmwareAI | 16/5/2024 | 17/6/2026 | Improper conditions check in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access. |