Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.26% | — | Sonicwall Connect TunnelAI | 11/10/2024 | 17/6/2026 | The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege escalation attack. | |
| Aplazada | Media (5.5) | 0.23% | — | Sonicwall Connect TunnelAI | 11/10/2024 | 17/6/2026 | The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of Service (DoS) attack. | |
| Analizada | Crítica (9.3) | 0.56% | — | Alisonic Sibylla Firmware | 27/9/2024 | 17/6/2026 | Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database. | |
| Analizada | Crítica (9.8) | 18% | ⚠ Explotación activa | Sonicwall Sonicos | 23/8/2024 | 21/9/2026 | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS… | |
| Aplazada | Alta (7.8) | 0.28% | — | Panasonic Fpwin PROAI | 21/8/2024 | 17/6/2026 | Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file. | |
| Modificada | Alta (7.5) | 0.70% | — | Sonicwall Sonicos | 18/7/2024 | 17/6/2026 | Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS). | |
| Modificada | Alta (8.8) | 1.9% | — | Sonicwall Netextender | 18/7/2024 | 17/6/2026 | Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update. | |
| Modificada | Crítica (9) | 15% | 💥 PoC | FreeradiusBroadcom Brocade SannavBroadcom Fabric Operating SystemSonicwall Sonicos | 9/7/2024 | 17/6/2026 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. | |
| Analizada | Crítica (9.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache Http ServerNetapp Ontap 9Sonicwall SMA 200 FirmwareSonicwall SMA 210 Firmware+3 | 1/7/2024 | 17/6/2026 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Analizada | Media (6.3) | 0.50% | — | Richardrodger Jsonic | 1/7/2024 | 17/6/2026 | rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Analizada | Crítica (9.8) | 0.88% | — | Richardrodger Jsonic | 1/7/2024 | 17/6/2026 | rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Aplazada | Crítica (9.8) | 10% | 💥 Exploit | Sonicwall AnalyzerAI | 21/6/2024 | 17/6/2026 | Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation. | |
| Modificada | Media (6.5) | 0.64% | — | Sonicwall Sonicos | 20/6/2024 | 17/6/2026 | Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function. | |
| Modificada | Alta (7.5) | 0.54% | — | Sonicwall Sonicos | 20/6/2024 | 17/6/2026 | Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Sonic Shopfloor.guideAI | 8/5/2024 | 17/6/2026 | A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbitrary SQL commands via the level2 parameter. | |
| Aplazada | Media (4.4) | 0.17% | — | Panasonic KW WatcherAI | 8/5/2024 | 17/6/2026 | A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory. | |
| Aplazada | Alta (7.8) | 0.19% | — | Sonic Dicom Media ViewerAI | 3/4/2024 | 17/6/2026 | Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application. | |
| Aplazada | Media (4.9) | 0.90% | — | Sonicwall Email Security ApplianceAI | 14/3/2024 | 17/6/2026 | An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance file system. | |
| Aplazada | Alta (8.3) | 1.1% | — | Sonicwall SonicosAI | 14/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code. | |
| Aplazada | Media (5.3) | 1.1% | — | Sonicwall SonicosAI | 14/3/2024 | 17/6/2026 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. | |
| Analizada | Media (6.3) | 0.43% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+1 | 24/2/2024 | 17/6/2026 | Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application. | |
| Analizada | Crítica (9.8) | 0.57% | — | Dell Enterprise Sonic Distribution | 15/2/2024 | 17/6/2026 | Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level. This is a Critical vulnerability affecting… | |
| Modificada | Crítica (9.8) | 0.75% | — | Sonicwall Sonicos | 8/2/2024 | 17/6/2026 | An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040. | |
| Modificada | Media (5.5) | 0.21% | — | Sonicwall Capture ClientSonicwall Netextender | 18/1/2024 | 17/6/2026 | SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability. |