Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 1.1% | — | Sonicwall SonicosAI | 14/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code. | |
| Aplazada | Media (5.3) | 1.1% | — | Sonicwall SonicosAI | 14/3/2024 | 17/6/2026 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. | |
| Modificada | Crítica (9.8) | 0.75% | — | Sonicwall Sonicos | 8/2/2024 | 17/6/2026 | An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040. | |
| Modificada | Alta (8.8) | 0.65% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel. | |
| Modificada | Alta (7.5) | 0.59% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash. | |
| Modificada | Alta (8.8) | 0.68% | — | Sonicwall Sonicos | 2/3/2023 | 17/6/2026 | SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes. | |
| Modificada | Alta (7.5) | 41% | 💥 PoC | Sonicwall Sonicos | 2/3/2023 | 17/6/2026 | A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash. | |
| Modificada | Alta (7.5) | 1.1% | — | Sonicwall Sonicos | 27/4/2022 | 17/6/2026 | Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable. | |
| Modificada | Crítica (9.8) | 76% | 💥 PoC | Sonicwall SonicosSonicwall Sonicosv | 25/3/2022 | 17/6/2026 | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall. | |
| Modificada | Alta (8.8) | 1.9% | — | Sonicwall Sonicos | 10/1/2022 | 17/6/2026 | A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions. | |
| Modificada | Alta (8.8) | 1.9% | — | Sonicwall Sonicos | 10/1/2022 | 17/6/2026 | A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions. | |
| Modificada | Media (6.1) | 13% | 💥 Exploit | Sonicwall Sonicos | 12/10/2021 | 17/6/2026 | A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains. | |
| Modificada | Alta (7.5) | 1.4% | — | Sonicwall SonicosSonicwall Sonicosv | 23/6/2021 | 17/6/2026 | A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Sonicwall Sonicos | 14/6/2021 | 17/6/2026 | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls. | |
| Modificada | Alta (7.4) | 18% | 💥 PoC | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Media (5.3) | 1.6% | — | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS… | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Sonicwall SonicosSonicwall Sonicosv | 12/10/2020 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in the firewall SSLVPN portal. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7,… |