Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.27% | — | Panasonic Fpwin PRO | 19/12/2023 | 17/6/2026 | Out-of-bouds read vulnerability in FPWin Pro version 7.7.0.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file. | |
| Modificada | Alta (7.8) | 0.27% | — | Panasonic Fpwin PRO | 19/12/2023 | 17/6/2026 | Stack-based buffer overflow in FPWin Pro version 7.7.0.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file. | |
| Modificada | Alta (8.8) | 0.91% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+1 | 5/12/2023 | 17/6/2026 | Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass. | |
| Analizada | Alta (7.2) | 76% | ⚠ Explotación activa | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+1 | 5/12/2023 | 17/6/2026 | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability. | |
| Modificada | Alta (7.5) | 0.76% | — | Common-services Sonice Retour | 17/11/2023 | 17/6/2026 | In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a… | |
| Modificada | Alta (7.3) | 0.29% | — | Sonicwall Netextender | 27/10/2023 | 17/6/2026 | SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system. | |
| Modificada | Alta (7.8) | 0.18% | — | Sonicwall Directory Services Connector | 27/10/2023 | 17/6/2026 | A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature. | |
| Modificada | Alta (7.5) | 0.58% | — | Common-services Sonice Etiquetage | 18/10/2023 | 17/6/2026 | In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can… | |
| Modificada | Alta (8.8) | 0.65% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel. | |
| Modificada | Alta (7.5) | 0.59% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the sonicwall.exp, prefs.exp URL endpoints lead to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS p ost-authentication Stack-Based Buffer Overflow vulnerability in the ssoStats-s.xml, ssoStats-s.wri URL endpoints leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication Stack-Based Buffer Overflow vulnerability in the getPacketReplayData.json URL endpoint leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication user assertion failure leads to Stack-Based Buffer Overflow vulnerability via main.cgi leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash. | |
| Modificada | Media (6.5) | 0.80% | — | Sonicwall Sonicos | 17/10/2023 | 17/6/2026 | SonicOS post-authentication stack-based buffer overflow vulnerability in the getBookmarkList.json URL endpoint leads to a firewall crash. | |
| Modificada | Alta (7.8) | 0.21% | — | Sonicwall Netextender | 3/10/2023 | 17/6/2026 | A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability. | |
| Modificada | Alta (7.8) | 0.19% | — | Sonicwall Netextender | 3/10/2023 | 17/6/2026 | A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality. | |
| Modificada | Alta (7.8) | 0.25% | — | Panasonic KW Watcher | 6/9/2023 | 17/6/2026 | Use after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.46% | — | Panasonic KW Watcher | 6/9/2023 | 17/6/2026 | Buffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.21% | — | Panasonic Control Fpwin PRO | 21/7/2023 | 17/6/2026 | A memory corruption vulnerability Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files. | |
| Modificada | Alta (7.8) | 0.21% | — | Panasonic Control Fpwin PRO | 21/7/2023 | 17/6/2026 | A type confusion vulnerability in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files. | |
| Modificada | Alta (7.8) | 0.28% | — | Panasonic Control Fpwin PRO | 21/7/2023 | 17/6/2026 | A stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files. | |
| Modificada | Crítica (9.8) | 1.0% | — | Sonicwall AnalyticsSonicwall Global Management System | 13/7/2023 | 17/6/2026 | SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. |