Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

2304 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.43%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
AplazadaMedia (5.1)0.49%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock…
AplazadaMedia (5.1)0.44%—Watchguard DimensionAI28/8/202628/8/2026
A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then executes in the browser session of any other user.
AplazadaAlta (8.7)0.54%—Watchguard Fireware OSAI28/8/20263/9/2026
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
AplazadaAlta (8.7)0.54%—Watchguard Fireware OSAI28/8/20263/9/2026
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
AplazadaAlta (8.7)0.54%—Watchguard Fireware OSAI28/8/20263/9/2026
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
AplazadaAlta (8.6)0.61%—Watchguard Fireware OSAI28/8/20263/9/2026
A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic.
AplazadaCrítica (9.3)0.47%—Watchguard Fireware OSAI28/8/20263/9/2026
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
AplazadaAlta (8.7)0.32%—Watchguard Fireware OSAI28/8/20263/9/2026
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
AplazadaAlta (8.7)0.32%—Watchguard Fireware OSAI28/8/20263/9/2026
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
AplazadaCrítica (9.3)0.46%—Watchguard Fireware OSAI28/8/20263/9/2026
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
AplazadaAlta (8.7)0.32%—Watchguard Fireware OSAI28/8/20263/9/2026
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
AplazadaCrítica (9.3)0.47%—Watchguard FirewareAI28/8/20263/9/2026
An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
AplazadaAlta (8.7)0.25%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service.
AplazadaCrítica (9.3)0.44%—Watchguard Fireware OSAI28/8/20263/9/2026
A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
AplazadaMedia (6.9)0.41%—Watchguard Fireware OSAI28/8/202628/8/2026
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration.
AplazadaCrítica (9.3)0.24%—Watchguard AgentAI25/8/202628/9/2026
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
AplazadaCrítica (9.4)0.41%—Watchguard AgentAI25/8/202628/9/2026
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.
AplazadaMedia (5.3)0.40%—CrosswatchAI21/8/20269/9/2026
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originating IP addresses, User-Agent strings, internal session IDs, and creation/expiry…
AnalizadaBaja (2.4)0.17%—Apple Watchos21/8/202624/8/2026
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.
AplazadaAlta (7.1)0.25%—Swatchly - Woocommerce Variation Swatches FOR ProductsAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
Pendiente de análisisAlta (8.4)0.54%—Openstack AodhAIOpenstack WatcherAI19/8/20269/9/2026
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch…
Pendiente de análisisAlta (8.8)0.15%—Dell Watchdog Timer DriverAI18/8/202620/8/2026
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
AplazadaAlta (7.6)0.21%—Watchfire Controller SoftwareAI30/7/20268/9/2026
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries…
AnalizadaAlta (8.8)0.43%—Apple SafariApple IpadosApple Iphone OSApple Macos+227/7/202628/7/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.