Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.7) | 0.61% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able to extract arbitrary information from the… | |
| Modificada | Media (5.4) | 0.15% | — | Nozominetworks CMCNozominetworks Guardian | 9/8/2023 | 17/6/2026 | In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session. | |
| Modificada | Alta (8.7) | 0.60% | — | Nozominetworks CMCNozominetworks Guardian | 4/5/2023 | 17/6/2026 | Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. | |
| Modificada | Media (4.8) | 0.33% | — | Medtronic Guardian Link 2 Transmitter Mmt-7730 FirmwareMedtronic Guardian Link 2 Transmitter Mmt-7731 FirmwareMedtronic Guardian Link 2 Transmitter Mmt-7738 FirmwareMedtronic Guardian Link 2 Transmitter Mmt-7775 Firmware+24 | 12/12/2022 | 17/6/2026 | A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge… | |
| Modificada | Media (5.1) | 0.23% | — | Digitalguardian Digital Guardian | 8/7/2022 | 17/6/2026 | Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the product) to disable some of the agent functionality and then exfiltrate files to an external USB device. | |
| Modificada | Alta (8.6) | 0.90% | — | Nozominetworks CMCNozominetworks Guardian | 24/3/2022 | 17/6/2026 | Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0.… | |
| Modificada | Alta (8.6) | 0.90% | — | Nozominetworks CMCNozominetworks Guardian | 24/3/2022 | 17/6/2026 | Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to… | |
| Modificada | Alta (7.4) | 0.97% | — | E2bn E2guardian | 23/12/2021 | 17/6/2026 | e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected… | |
| Modificada | Alta (8.6) | 1.1% | — | Nozominetworks Central Management ControlNozominetworks Guardian | 22/2/2021 | 17/6/2026 | Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior… | |
| Modificada | Alta (8.6) | 2.8% | — | Nozominetworks Central Management ControlNozominetworks Guardian | 22/2/2021 | 17/6/2026 | OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3… | |
| Modificada | Alta (7.3) | 0.90% | — | Nozominetworks Guardian | 30/6/2020 | 17/6/2026 | Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. | |
| Modificada | Media (6.1) | 0.69% | — | Nozominetworks Guardian | 30/6/2020 | 17/6/2026 | Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name. | |
| Modificada | Alta (8.8) | 1.5% | — | Guardianproject Stegdetect | 23/10/2018 | 17/6/2026 | Stegdetect through 2018-05-26 has an out-of-bounds write in f5_compress in the f5.c file. | |
| Modificada | Media (6.1) | 1.0% | — | Theguardian Html-janitor | 4/6/2018 | 17/6/2026 | html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed. | |
| Modificada | Media (6.5) | 2.2% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue. | |
| Modificada | Media (6.5) | 1.1% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 has an XXE issue. | |
| Modificada | Media (6.5) | 1.1% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role. | |
| Modificada | Alta (8.8) | 5.1% | — | Digitalguardian Management Console | 20/4/2018 | 17/6/2026 | Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality. | |
| Modificada | Media (4.3) | 1.8% | — | Canon-its Accessguardian | 13/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Canon IT Solutions Inc. ACCESSGUARDIAN 3.0.14 and earlier, and 3.5.6 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to authentication. | |
| Modificada | Alta (7.2) | 0.61% | 💥 Exploit | Overlandstorage Snap Server 410Overlandstorage Guardianos | 13/1/2010 | 16/6/2026 | The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the CLI user and without sufficient restriction on shell escapes, which allows local users to gain privileges using the "!" character within less to access a privileged shell. | |
| Modificada | Media (5.4) | 2.4% | — | Smoothwall NetworkguardianSmoothwall SchoolguardianSmoothwall Smoothguardian | 4/3/2009 | 16/6/2026 | SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other… | |
| Modificada | Media (4.6) | 0.33% | — | Credant Mobile Guardian Shield - Windows | 30/5/2007 | 16/6/2026 | Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory image. NOTE: This issue crosses privilege boundaries because the… | |
| Modificada | Media (5) | 1.4% | — | Daniel Barron Dansguardian | 31/12/2004 | 16/6/2026 | DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request. | |
| Modificada | Media (5) | 1.4% | — | Daniel Barron Dansguardian | 31/12/2004 | 16/6/2026 | Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache. | |
| Modificada | Alta (7.5) | 1.9% | — | Daniel Barron Dansguardian | 31/12/2004 | 16/6/2026 | DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename. |