Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
972 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.6) | 0.61% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Watchguard FirewareAI | 28/8/2026 | 3/9/2026 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.25% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service. | |
| Aplazada | Crítica (9.3) | 0.44% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code. | |
| Aplazada | Media (6.9) | 0.41% | — | Watchguard Fireware OSAI | 28/8/2026 | 28/8/2026 | A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration. | |
| Aplazada | Crítica (9.3) | 0.24% | — | Watchguard AgentAI | 25/8/2026 | 28/9/2026 | Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Watchguard AgentAI | 25/8/2026 | 28/9/2026 | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. | |
| En análisis | Media (4.3) | 0.13% | — | Intel Software Guard Extensions Data Center Attestation PrimitivesAI | 11/8/2026 | 29/9/2026 | Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur… | |
| Aplazada | Baja (1.8) | 0.17% | — | Mullvad Wireguard.sysAI | 10/8/2026 | 12/8/2026 | A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicly available and might be used. The… | |
| Aplazada | Alta (7.5) | 0.50% | — | Admin Safety GuardAI | 8/8/2026 | 26/8/2026 | The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Siteguard WP PluginAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | |
| Aplazada | Baja (1.3) | 0.24% | — | Omicronenergy StationguardAI | 6/8/2026 | 3/9/2026 | OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system… | |
| Aplazada | Alta (8.1) | 0.42% | — | Omicronenergy StationguardAI | 6/8/2026 | 3/9/2026 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can… | |
| Analizada | Alta (8.2) | 0.46% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it only base64-decodes the JWT header and… | |
| Analizada | Media (6.9) | 0.48% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is associated with program file lib/guardian/permissions.ex and program routines… | |
| Analizada | Media (6.9) | 0.48% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. When encode/3 in… | |
| Analizada | Media (6.9) | 0.48% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom/1. base_key/1 in… |