Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
2304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.43% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover. | |
| Aplazada | Media (5.1) | 0.49% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock… | |
| Aplazada | Media (5.1) | 0.44% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then executes in the browser session of any other user. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.6) | 0.61% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Watchguard FirewareAI | 28/8/2026 | 3/9/2026 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.25% | — | Watchguard DimensionAI | 28/8/2026 | 28/8/2026 | WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service. | |
| Aplazada | Crítica (9.3) | 0.44% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code. | |
| Aplazada | Media (6.9) | 0.41% | — | Watchguard Fireware OSAI | 28/8/2026 | 28/8/2026 | A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration. | |
| Aplazada | Crítica (9.3) | 0.24% | — | Watchguard AgentAI | 25/8/2026 | 28/9/2026 | Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Watchguard AgentAI | 25/8/2026 | 28/9/2026 | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. | |
| Aplazada | Media (5.3) | 0.40% | — | CrosswatchAI | 21/8/2026 | 9/9/2026 | CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originating IP addresses, User-Agent strings, internal session IDs, and creation/expiry… | |
| Analizada | Baja (2.4) | 0.17% | — | Apple Watchos | 21/8/2026 | 24/8/2026 | This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts. | |
| Aplazada | Alta (7.1) | 0.25% | — | Swatchly - Woocommerce Variation Swatches FOR ProductsAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |
| Pendiente de análisis | Alta (8.4) | 0.54% | — | Openstack AodhAIOpenstack WatcherAI | 19/8/2026 | 9/9/2026 | In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch… | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Dell Watchdog Timer DriverAI | 18/8/2026 | 20/8/2026 | Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. | |
| Aplazada | Alta (7.6) | 0.21% | — | Watchfire Controller SoftwareAI | 30/7/2026 | 8/9/2026 | The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries… | |
| Analizada | Alta (8.8) | 0.43% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 27/7/2026 | 28/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. |