Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

183 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.48%—Watchguard FireboxAI15/9/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface…
AplazadaMedia (4.8)0.54%—Watchguard FireboxAI16/5/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management…
AplazadaMedia (4.8)0.45%—Watchguard Fireware OSAI16/5/20258/8/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.
AplazadaMedia (6.3)0.15%—Watchguard Terminal Services AgentAI28/3/20258/8/2026
The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.
AplazadaMedia (6.3)0.14%—Watchguard Mobile VPN With SSL ClientAI28/3/20258/8/2026
The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.
AplazadaMedia (4.8)0.55%—Watchguard FireboxAI14/2/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of…
ModificadaMedia (4.8)0.30%—Watchguard Fireware14/2/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of…
ModificadaMedia (5.1)0.24%—Watchguard Fireware14/2/20258/8/2026
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious…
AplazadaMedia (6.5)1.3%💥 PoCWatchguard Fireware OSAIWatchguard FireboxAIWatchguard XTMAI28/1/202517/6/2026
An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances
AnalizadaAlta (7.8)0.28%—Watchguard Panda Dome30/12/202417/6/2026
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AplazadaAlta (8.5)0.19%—Watchguard EpdrAIPanda Ad360AIPanda DomeAI8/11/20248/8/2026
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.
ModificadaAlta (8.7)0.64%—Watchguard Single Sign-on Client25/9/20248/8/2026
Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing…
ModificadaCrítica (9.3)0.58%—Watchguard Authentication Gateway25/9/20248/8/2026
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and…
ModificadaCrítica (9.3)1.2%💥 PoCWatchguard Authentication GatewayWatchguard Single Sign-on Client25/9/20248/8/2026
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an…
ModificadaAlta (8.6)1.1%—Watchguard Fireware9/7/20247/8/2026
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.
ModificadaAlta (8.6)0.34%—Watchguard Mobile VPN With SSL9/7/20247/8/2026
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.
AplazadaAlta (7.8)0.72%—Watchguard Authpoint Password ManagerAI16/5/202417/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for…
AnalizadaAlta (7.6)4.1%💥 PoCFortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+56/5/202417/6/2026
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that…
ModificadaMedia (5.5)0.16%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user.
ModificadaMedia (5.5)0.17%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by sending a crafted message to a named pipe.
ModificadaMedia (6.7)0.18%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.
ModificadaAlta (7.8)0.16%—Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware5/10/202317/6/2026
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
ModificadaMedia (6.5)0.40%—Watchguard Panda Security VPN13/7/202317/6/2026
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.
ModificadaMedia (5.4)0.59%—Watchguard Fireware6/9/202217/6/2026
A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web interface by sending crafted requests to exposed management ports. This is fixed in Fireware OS…
ModificadaAlta (7.8)0.23%—Watchguard Fireware6/9/202217/6/2026
WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access) to elevate their privileges and execute code with root permissions. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Orbitaley — Vulnerabilidades