Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1724 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 17/6/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (7.1) | 0.91% | — | Endian Firewall Community | 2/4/2026 | 17/6/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, which is then passed to… | |
| Modificada | Media (5.5) | 0.18% | — | FirewalldRedhat Enterprise Linux | 27/3/2026 | 6/10/2026 | A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized… | |
| Aplazada | Alta (7.1) | 0.18% | — | Rsjoomla RsfirewallAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a through <= 1.1.45. | |
| Analizada | Alta (8.6) | 0.35% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE | 25/3/2026 | 17/9/2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak,… | |
| Analizada | Alta (7.3) | 0.12% | — | Forcepoint Next Generation Firewall | 11/3/2026 | 17/6/2026 | Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10. | |
| Analizada | Media (6.5) | 0.10% | — | Cisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input. An attacker with a low-privileged… | |
| Analizada | Media (6.8) | 0.17% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This… | |
| Analizada | Media (5.7) | 0.20% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This… | |
| Analizada | Media (6.5) | 0.16% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to corrupt memory on an affected device, resulting in a denial of service (DoS) condition. This… | |
| Analizada | Media (6.5) | 0.20% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf… | |
| Analizada | Media (4.3) | 0.21% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. This vulnerability… | |
| Analizada | Media (5.7) | 0.26% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. If OSPF authentication is enabled, the attacker must know the secret key to… | |
| Analizada | Media (6.7) | 0.34% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid… | |
| Analizada | Crítica (10) | 43% | ⚠ Explotación activa💥 PoC | Cisco Secure Firewall Management Center | 4/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.… | |
| Analizada | Media (5.3) | 0.33% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS)… | |
| Analizada | Alta (7.7) | 0.32% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS)… | |
| Analizada | Alta (8.6) | 0.36% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access… | |
| Analizada | Media (6.1) | 0.27% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based… | |
| Analizada | Alta (8.6) | 0.36% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing… | |
| Analizada | Alta (7.7) | 0.29% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to cause the device to reload unexpectedly,… | |
| Analizada | Crítica (10) | 88% | ⚠ Explotación activa💥 Exploit | Cisco Secure Firewall Management Center | 4/3/2026 | 16/9/2026 | — | |
| Analizada | Media (5.8) | 0.40% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device. This vulnerability is due to improper error handling when an… |