Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Sophos XG Firewall Firmware | 10/7/2020 | 17/6/2026 | A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have… | |
| Analizada | Crítica (9.8) | 11% | ⚠ Explotación activa | Sophos XG Firewall Firmware | 29/6/2020 | 17/6/2026 | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x. | |
| Modificada | Alta (7.5) | 1.6% | — | Cujo Smart Firewall Firmware | 31/10/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. When parsing labels in mDNS packets, the firewall unsafely handles label compression pointers, leading to an uncontrolled recursion that eventually exhausts the stack, crashing the mdnscap… | |
| Modificada | Alta (7.8) | 77% | 💥 Exploit | Cisco Unified Computing System Manager FirmwareCisco Firepower 9300 Security Appliance FirmwareCisco Firepower 4100 Next-generation Firewall Firmware | 2/11/2017 | 17/6/2026 | A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the device, aka Command Injection. The vulnerability is due to… | |
| Modificada | Alta (8.8) | 2.3% | — | Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware | 8/8/2016 | 17/6/2026 | Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557. | |
| Modificada | Alta (7.8) | 1.9% | 💥 Exploit | Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware | 8/8/2016 | 17/6/2026 | The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567. | |
| Modificada | Media (6.5) | 1.8% | — | Cisco Rv215w Wireless-n VPN Router FirmwareCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130w Wireless-n Multifunction VPN Router Firmware | 19/6/2016 | 17/6/2026 | Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote authenticated users to cause a denial of service (device reload) via crafted configuration commands in… | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv215w Wireless-n VPN Router Firmware | 19/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka… | |
| Modificada | Crítica (9.8) | 4.8% | — | Cisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router FirmwareCisco Rv110w Wireless-n VPN Firewall Firmware | 19/6/2016 | 17/6/2026 | The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP request, aka Bug ID CSCux82428. | |
| Modificada | Media (4.3) | 1.3% | — | Mcafee Unified Threat Management Firewall Firmware | 15/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/cgix/help in McAfee Unified Threat Management (UTM) Firewall (formerly SnapGear) firmware 3.0.0 through 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the page parameter. |