Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

972 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.1%—IBM Security Guardium28/11/202317/6/2026
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
ModificadaMedia (6)0.31%—Fortra Digital Guardian Agent22/11/202317/6/2026
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
ModificadaMedia (5.4)0.38%—Open-xchange OX Guard2/11/202317/6/2026
Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing…
ModificadaMedia (5.5)0.16%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user.
ModificadaMedia (5.5)0.17%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by sending a crafted message to a named pipe.
ModificadaMedia (6.7)0.18%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.
ModificadaAlta (7.8)0.16%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
ModificadaMedia (5.3)0.47%—IBM Security Guardium4/10/202317/6/2026
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897.
ModificadaMedia (5.4)0.40%—ISL Arp-guard20/9/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaAlta (8.2)0.64%—Nozominetworks CMCNozominetworks Guardian19/9/202317/6/2026
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker to crash the IDS module by sending specially crafted malformed network packets. During the…
AnalizadaAlta (8.7)0.62%—Nozominetworks CMCNozominetworks Guardian19/9/202317/6/2026
A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality. Authenticated users may be able to execute arbitrary SQL statements on the DBMS used by the web application.
ModificadaCrítica (9.2)0.60%—Nozominetworks CMCNozominetworks Guardian19/9/202317/6/2026
A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted…
ModificadaCrítica (9.8)1.2%—Exagate Sysguard 3001 Firmware14/9/202317/6/2026
Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.
ModificadaMedia (6.5)0.71%—IBM Security Guardium5/9/202317/6/2026
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
ModificadaMedia (5.3)0.46%—IBM Guardium Cloud KEY Manager28/8/202317/6/2026
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 248133.
ModificadaAlta (7.5)0.47%—IBM Guardium Cloud KEY Manager28/8/202317/6/2026
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 248126.
ModificadaCrítica (9.8)0.70%—IBM Guardium Cloud KEY Manager28/8/202317/6/2026
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the system, caused by an angular template injection flaw. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the…
ModificadaAlta (7.5)0.77%—IBM Security Guardium28/8/202317/6/2026
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
ModificadaMedia (5.4)0.56%—IBM Security Guardium27/8/202317/6/2026
IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614.
ModificadaMedia (5.3)0.60%—IBM Security Guardium27/8/202317/6/2026
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
ModificadaMedia (5.4)0.34%—IBM Security Guardium27/8/202317/6/2026
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292.
ModificadaMedia (5.4)0.42%—IBM Security Guardium27/8/202317/6/2026
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291.
ModificadaMedia (5.4)0.37%—IBM Security Guardium27/8/202317/6/2026
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 240905.
ModificadaAlta (8.8)1.3%—IBM Security Guardium27/8/202317/6/2026
IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901.
AnalizadaAlta (7.5)0.81%—Adguard DNS25/8/202317/6/2026
AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.
Orbitaley — Vulnerabilidades