Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.2% | — | Sonicwall Sonicos | 20/11/2025 | 17/6/2026 | A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash. | |
| Analizada | Media (4.5) | 0.48% | — | Sonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 500v Firmware | 31/10/2025 | 17/6/2026 | A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data. | |
| Aplazada | Alta (8.4) | 0.16% | — | Panasonic AutodownloaderAI | 3/10/2025 | 17/6/2026 | Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead to loading a crafted DLL file in the same directory. | |
| Aplazada | Baja (2.1) | 0.26% | — | Airsonic-advancedAI | 18/9/2025 | 17/6/2026 | A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Performing manipulation results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Media (6.9) | 1.1% | — | Panasonic CL4 6NX PlusAIPanasonic CL4 6nx-j PlusAI | 6/8/2025 | 17/6/2026 | OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. An arbitrary OS command may be executed on the system with a certain non-administrative user privilege. | |
| Analizada | Alta (7.5) | 0.37% | — | Dell Enterprise Sonic OS | 4/8/2025 | 17/6/2026 | Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication. | |
| Aplazada | Crítica (9.3) | 2.8% | 💥 Exploit | Raidsonic Ib-nas5220AIRaidsonic Ib-nas4220AI | 1/8/2025 | 16/6/2026 | An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-NAS4220—via the unauthenticated timeHandler.cgi endpoint exposed through the web interface. The CGI script fails to properly sanitize user-supplied input in the timeZone parameter of a POST request,… | |
| Analizada | Crítica (9.8) | 0.91% | — | Sonicwall Sonicos | 29/7/2025 | 17/6/2026 | Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. | |
| Analizada | Media (6.1) | 64% | — | Sonicwall SMA 500v FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 Firmware | 23/7/2025 | 17/6/2026 | A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code. | |
| Analizada | Alta (7.5) | 30% | — | Sonicwall SMA 500v FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 Firmware | 23/7/2025 | 17/6/2026 | A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. | |
| Analizada | Alta (7.3) | 56% | — | Sonicwall SMA 500v FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 Firmware | 23/7/2025 | 17/6/2026 | A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. | |
| Analizada | Crítica (9.1) | 14% | — | Sonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 500v Firmware | 23/7/2025 | 17/6/2026 | An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution. | |
| Aplazada | Media (5.4) | 0.15% | — | WritesonicAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Writesonic Writesonic writesonic allows Cross Site Request Forgery.This issue affects Writesonic: from n/a through <= 1.0.5. | |
| Analizada | Baja (2) | 0.57% | — | Upsonic | 19/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2) | 0.79% | — | Upsonic | 19/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of the argument file.filename leads to path traversal. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.2) | 20% | — | Sonicwall SMA 100 FirmwareSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 Firmware+2 | 7/5/2025 | 17/6/2026 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance. | |
| Analizada | Alta (8.8) | 2.9% | — | Sonicwall SMA 100 FirmwareSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 Firmware+2 | 7/5/2025 | 17/6/2026 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable. | |
| Analizada | Alta (8.8) | 6.5% | — | Sonicwall SMA 100 FirmwareSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 Firmware+2 | 7/5/2025 | 17/6/2026 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. | |
| Modificada | Alta (7.2) | 0.34% | — | Sonicwall Sma1000 Firmware | 30/4/2025 | 17/6/2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location. | |
| Aplazada | Alta (7.5) | 0.83% | — | Sonicwall SonicosAI | 23/4/2025 | 17/6/2026 | A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition. | |
| Aplazada | Media (6.1) | 0.35% | — | Sonicwall Connect TunnelAI | 16/4/2025 | 17/6/2026 | A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this results in unauthorized file overwrite, potentially leading to denial of service or file corruption. | |
| Aplazada | Alta (7.2) | 0.41% | — | Sonicwall NetextenderAI | 10/4/2025 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths. | |
| Aplazada | Alta (7.2) | 0.37% | — | Sonicwall NetextenderAI | 10/4/2025 | 17/6/2026 | A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion. | |
| Aplazada | Alta (7.2) | 0.35% | — | Sonicwall NetextenderAI | 10/4/2025 | 17/6/2026 | An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker to modify configurations. | |
| Aplazada | Alta (7.5) | 0.22% | — | Panasonic IR Control HUBAI | 10/4/2025 | 17/6/2026 | Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unauthorized firmware onto the device. |