Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1724 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (8.7) | 0.83% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not… | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security Manager | 14/2/2024 | 17/6/2026 | When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security Manager | 14/2/2024 | 17/6/2026 | When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Media (6.7) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873. Note: Software… | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Advanced Firewall Manager | 14/2/2024 | 17/6/2026 | For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Advanced Firewall Manager | 14/2/2024 | 17/6/2026 | When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate. NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Crítica (9.8) | 1.8% | — | Malwarebytes Binisoft Windows Firewall Control | 4/2/2024 | 17/6/2026 | Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes. | |
| Modificada | Alta (7.6) | 0.43% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require… | |
| Modificada | Baja (2.7) | 0.34% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks of this… | |
| Modificada | Baja (3) | 0.33% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. While the vulnerability is… | |
| Modificada | Alta (8.6) | 47% | 💥 Exploit | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+3 | 8/1/2024 | 17/6/2026 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.23% | — | Cleantalk Spam Protection, Antispam, Firewall | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20. | |
| Modificada | Media (4.3) | 0.41% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 12/12/2023 | 11/8/2026 | A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the… | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Baja (3.3) | 0.21% | — | Samsung Firewall | 7/11/2023 | 17/6/2026 | Implicit intent hijacking vulnerability in Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 in Android 12 and 14.1.00.7 in Android 13 allows 3rd party application to tamper the database of Firewall. | |
| Modificada | Media (5.3) | 0.43% | — | Cisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP… | |
| Modificada | Media (6.1) | 0.38% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a… | |
| Modificada | Media (4.3) | 0.29% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and… | |
| Modificada | Media (5.3) | 0.56% | — | SnortCisco Secure Firewall Threat DefenseCisco IOS XE | 1/11/2023 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access control policies are being populated. An attacker… | |
| Modificada | Alta (8.8) | 1.1% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does… | |
| Modificada | Alta (8.8) | 0.89% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to… | |
| Modificada | Alta (8.6) | 0.64% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of… | |
| Modificada | Alta (8.6) | 0.69% | — | Cisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of… | |
| Modificada | Media (5.8) | 0.52% | — | Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Unified Threat DefenseCisco Meraki MX Security Appliance Firmware | 1/11/2023 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this… |