Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.89%—Stormshield Network Security29/12/202117/6/2026
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.
ModificadaMedia (5.9)100%—Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaMedia (4.8)0.59%—Mcafee Network Security Manager9/12/202117/6/2026
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.
AnalizadaAlta (7.5)25%—Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaMedia (5.9)1.3%—IBM Qradar Network Security8/11/202117/6/2026
IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340.
ModificadaMedia (5.4)0.50%—IBM Qradar Network Security8/11/202117/6/2026
IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174269.
ModificadaMedia (5.9)0.59%—IBM Qradar Network Security8/11/202117/6/2026
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques. IBM X-Force ID: 17467.
ModificadaAlta (7.5)0.94%—Stormshield Network Security1/7/202117/6/2026
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
ModificadaAlta (8.8)12%—Sonicwall Network Security Manager27/5/202117/6/2026
A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.
ModificadaMedia (6.5)0.96%—Trendmicro Home Network Security27/5/202117/6/2026
Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code…
ModificadaAlta (7.8)0.39%—Trendmicro Home Network Security27/5/202117/6/2026
Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged…
ModificadaAlta (7.8)0.43%—Trendmicro Home Network Security26/5/202117/6/2026
Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl to escalate privileges on affected devices. An attacker must first obtain the ability to execute low-privileged code on the…
ModificadaAlta (7.5)0.99%—Stormshield Network SecurityStormshield Network Security6/5/202117/6/2026
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
ModificadaAlta (7.5)1.1%—Trendmicro Home Network Security5/5/202117/6/2026
Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31517.
ModificadaAlta (7.5)1.1%—Trendmicro Home Network Security5/5/202117/6/2026
Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31518.
ModificadaMedia (5.5)1.3%—Netasq Project NetasqStormshield Network SecurityClamav19/3/202117/6/2026
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.
ModificadaMedia (5.3)1.1%—Stormshield Network Security2/3/202117/6/2026
A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to…
ModificadaMedia (6.5)0.53%—Mcafee Network Security Management5/1/202117/6/2026
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
ModificadaAlta (7.5)1.4%—Mozilla Network Security ServicesSiemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+522/10/202017/6/2026
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
ModificadaCrítica (9.8)3.6%—Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 FirmwareSiemens Ruggedcom ROX Rx1501 Firmware+922/10/202017/6/2026
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
ModificadaMedia (6.5)2.0%—Mozilla Network Security ServicesSiemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+522/10/202017/6/2026
In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
ModificadaAlta (7.5)3.9%—Mozilla Network Security ServicesRedhat Enterprise LinuxFedoraproject FedoraOracle Communications Offline Mediation Controller+220/10/202017/6/2026
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS…
ModificadaAlta (7.5)2.0%—MPD Project MPDStormshield Network Security6/10/202017/6/2026
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.
ModificadaCrítica (9.8)3.0%—MPD Project MPDStormshield Network Security6/10/202017/6/2026
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).
ModificadaAlta (7.8)0.37%—Mcafee Network Security Management3/7/202017/6/2026
Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to gain unauthorised access to the root account via execution of carefully crafted commands from the restricted command line interface (CLI).