Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

972 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.72%—Watchguard Authpoint Password ManagerAI16/5/202417/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for…
AnalizadaMedia (4.4)0.17%—IBM Security Guardium16/5/202417/6/2026
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.
AnalizadaAlta (7.8)0.19%—IBM Security Guardium14/5/202417/6/2026
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
AnalizadaMedia (6.5)0.68%—IBM Security Guardium14/5/202417/6/2026
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
AnalizadaAlta (8.8)1.0%—IBM Security Guardium14/5/202417/6/2026
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
AnalizadaAlta (7.6)4.1%💥 PoCFortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+56/5/202417/6/2026
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that…
AplazadaAlta (7.6)0.25%—DPS Telecom Netguardian DIN Remote Telemetry UnitAI30/4/202417/6/2026
Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (XSS) and Cross-Site…
AnalizadaAlta (7.5)0.64%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 Firmware+415/4/202417/6/2026
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will…
AplazadaAlta (8.2)0.55%—Nozominetworks GuardianAI10/4/202417/6/2026
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links,…
AnalizadaAlta (8.2)1.4%—IBM Security Guardium KEY Lifecycle Manager29/2/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 247599.
AnalizadaAlta (8.8)1.1%—IBM Security Guardium KEY Lifecycle Manager29/2/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.
AnalizadaAlta (8.8)1.4%—IBM Security Guardium KEY Lifecycle Manager28/2/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.
AnalizadaAlta (8.8)0.56%—IBM Security Guardium KEY Lifecycle Manager28/2/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.
AnalizadaAlta (8.1)0.36%—Br-automation Automation StudioBr-automation Technology Guarding22/2/202417/6/2026
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
ModificadaAlta (7.5)0.65%—Rockwellautomation Controllogix 5570 Controller FirmwareRockwellautomation Guardlogix 5570 Controller FirmwareRockwellautomation Controllogix 5570 Redundant Controller Firmware31/1/202417/6/2026
A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device will restart itself to recover from the MNRF.
ModificadaMedia (5.4)0.26%—Guardiansoft Guardian29/1/202417/6/2026
In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed value may be visible to the rest of the stack’s tenants.
ModificadaMedia (6.3)0.45%—Nozominetworks CMCNozominetworks Guardian15/1/202417/6/2026
A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the underlying system may be able to extract…
ModificadaAlta (7.2)0.48%—Westguardsolutions WS Form29/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WS Form WS Form LITE – Drag & Drop Contact Form Builder for WordPress.This issue affects WS Form LITE – Drag & Drop Contact Form Builder for WordPress: from n/a through 1.9.170.
ModificadaMedia (5.4)0.44%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522.
ModificadaMedia (4.3)0.52%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
ModificadaMedia (5.3)0.76%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.
ModificadaCrítica (9.1)0.97%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.
ModificadaAlta (8.8)0.84%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.
ModificadaAlta (7.5)0.61%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.
ModificadaAlta (7.2)0.74%—Guardgiant19/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.