Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.69%—Tencentmusic Supersonic3/4/202517/6/2026
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may…
AplazadaMedia (5.4)0.16%—Sonicwall AnalyticsAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jordan.hatch Infusionsoft Analytics infusionsoft-web-tracker allows Cross Site Request Forgery.This issue affects Infusionsoft Analytics: from n/a through <= 2.0.
AplazadaMedia (5.5)0.20%—Sonicwall NetextenderAI30/1/202517/6/2026
A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.
AnalizadaMedia (4.9)0.34%—Dell Enterprise Sonic Distribution30/1/202517/6/2026
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaCrítica (9.8)23%⚠ Explotación activaSonicwall Sma8200vSonicwall Sma6200 FirmwareSonicwall Sma6210 FirmwareSonicwall Sma7200 Firmware+423/1/202524/9/2026
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
AplazadaMedia (6.6)0.90%—Panasonic Ud-lt2 FirmwareAI22/1/202517/6/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.
AplazadaCrítica (9.1)0.50%—Sonicwall Ssl-vpnAIMicrosoft Active DirectoryAI9/1/202517/6/2026
SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling…
AplazadaCrítica (9.8)0.80%—Sonicwall SonicosAI9/1/202517/6/2026
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
AplazadaMedia (4.9)0.64%—Sonicwall SonicosAI9/1/202517/6/2026
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
AplazadaAlta (7.2)0.71%—Sonicwall SonicosAI9/1/202517/6/2026
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
AplazadaAlta (7.2)0.80%—Sonicwall SonicosAI9/1/202517/6/2026
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
AplazadaAlta (7.8)0.34%—Sonicwall SonicoscloudAI9/1/202517/6/2026
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
AplazadaAlta (7.5)0.74%—Sonicwall SonicosAI9/1/202517/6/2026
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 ExploitSonicwall Sonicos9/1/20254/8/2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
AplazadaCrítica (9.8)1.0%—Sonicwall SonicosAI9/1/202517/6/2026
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
AnalizadaAlta (8.1)13%💥 PoCSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+15/12/202417/6/2026
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.
AnalizadaMedia (5.3)0.33%—Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+15/12/202417/6/2026
Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.
AnalizadaMedia (6.3)0.23%—Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+15/12/202417/6/2026
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.
AnalizadaAlta (8.1)1.0%—Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+15/12/202417/6/2026
A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.
AnalizadaAlta (7.5)0.94%—Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+15/12/202417/6/2026
Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
AplazadaAlta (7.5)0.57%—Panasonic Ud-lt1 FirmwareAIPanasonic Ud-lt1/ex FirmwareAI5/12/202417/6/2026
Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configuration settings of the…
AnalizadaAlta (7.2)1.4%—Dell Enterprise Sonic Distribution8/11/202417/6/2026
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical…
AnalizadaAlta (7.2)1.4%—Dell Enterprise Sonic Distribution8/11/202417/6/2026
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical…
AnalizadaCrítica (9.8)0.52%—Dell Enterprise Sonic Distribution8/11/202417/6/2026
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Dell recommends…
AplazadaAlta (7.5)0.58%—Sonicwall Sma1000AI11/10/202417/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.
Orbitaley — Vulnerabilidades