Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
2304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.14% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 14/9/2026 | 18/9/2026 | A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An archive may be able to bypass Gatekeeper. | |
| Analizada | Baja (3.3) | 0.15% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 18/9/2026 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory. | |
| Analizada | Media (4.7) | 0.11% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 18/9/2026 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination. | |
| Analizada | Alta (7.1) | 0.15% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 18/9/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory. | |
| Analizada | Media (4.7) | 0.11% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 18/9/2026 | A race condition was addressed with improved state handling. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination. | |
| Analizada | Alta (7.8) | 0.17% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 14/9/2026 | 18/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory. | |
| Analizada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 18/9/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel… | |
| Pendiente de análisis | Baja (2.1) | 0.10% | — | Android WatchAIAndroid Watch PluginAI | 9/9/2026 | 10/9/2026 | Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information. | |
| Aplazada | Alta (8.8) | 0.94% | — | Watchguard FireboxAI | 9/9/2026 | 9/9/2026 | The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to… | |
| Aplazada | Alta (7) | 0.25% | — | Watchguard DimensionAI | 8/9/2026 | 8/9/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page. | |
| Pendiente de análisis | Crítica (9.3) | 0.92% | — | Moos-ivp UmemwatchAI | 3/9/2026 | 8/9/2026 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls. | |
| Aplazada | Media (6.5) | 0.22% | — | Product Variations Swatches FOR WoocommerceAI | 3/9/2026 | 4/9/2026 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Watchman-site7AI | 2/9/2026 | 3/9/2026 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server. | |
| Aplazada | Media (6.9) | 0.43% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request. | |
| Aplazada | Media (6.3) | 0.41% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed… | |
| Aplazada | Media (4.8) | 0.30% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate. | |
| Aplazada | Media (4.6) | 0.47% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL. | |
| Aplazada | Alta (8.6) | 0.71% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests. | |
| Aplazada | Alta (8.6) | 0.62% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests. | |
| Aplazada | Alta (8.6) | 0.71% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests. | |
| Aplazada | Alta (8.4) | 0.23% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's… | |
| Aplazada | Media (5.1) | 0.44% | — | Watchguard Dimension Database ServerAI | 28/8/2026 | 28/8/2026 | A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. | |
| Aplazada | Media (5.1) | 0.44% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. | |
| Aplazada | Media (5.1) | 0.44% | — | Watchguard Dimension Email ServerAI | 28/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. | |
| Aplazada | Media (5.3) | 0.39% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. |