Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

183 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—Watchguard Fireware6/9/202217/6/2026
An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
ModificadaAlta (7.5)2.0%—Watchguard Fireware6/9/202217/6/2026
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
ModificadaCrítica (9.1)1.3%—Watchguard Fireware7/6/202217/6/2026
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
AnalizadaCrítica (9.8)78%⚠ Explotación activa💥 ExploitWatchguard Fireware4/3/202217/6/2026
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
ModificadaMedia (6.5)0.90%—Watchguard Fireware24/2/202217/6/2026
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to modify privileged management user credentials. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
ModificadaAlta (8.8)1.3%—Watchguard Fireware24/2/202217/6/2026
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
ModificadaAlta (8.8)2.1%—Watchguard Fireware24/2/202217/6/2026
A systemd stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through…
ModificadaAlta (8.8)2.1%—Watchguard Fireware24/2/202217/6/2026
A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through…
ModificadaAlta (8.8)1.8%—Watchguard Fireware24/2/202217/6/2026
An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before…
ModificadaMedia (6.5)0.70%—Watchguard Fireware24/2/202217/6/2026
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve certificate private keys. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
AnalizadaAlta (8.8)11%⚠ Explotación activaWatchguard Fireware24/2/202217/6/2026
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.
ModificadaAlta (7.8)0.37%—Watchguard Panda Antivirus13/1/202217/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the use of named…
ModificadaCrítica (9.8)74%—Nagios XI Watchguard Wizard13/8/202117/6/2026
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).
ModificadaAlta (7.5)2.8%💥 ExploitWatchguard AD Helper Firmware12/3/202017/6/2026
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.
ModificadaMedia (6.1)1.2%—Watchguard Fireware XTM7/2/202017/6/2026
A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script.
ModificadaMedia (6.1)0.77%—Watchguard Xmt515 Firmware7/1/202017/6/2026
A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to execute JavaScript in the victim's browser by tricking the victim into clicking on a crafted link. The payload was tested in Microsoft Internet Explorer 11.418.18362.0 and Microsoft Edge…
ModificadaMedia (6.1)0.94%—Watchguard Fireware23/8/201917/6/2026
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
ModificadaCrítica (9.8)1.3%—Watchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 FirmwareWatchguard Ap300 Firmware2/5/201817/6/2026
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. Incorrect validation of the "old password" field in the change password form allows an attacker to bypass validation of this field.
ModificadaAlta (8.8)6.5%💥 ExploitWatchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 FirmwareWatchguard Ap300 Firmware2/5/201817/6/2026
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as…
ModificadaAlta (7.8)1.5%💥 ExploitWatchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 Firmware30/4/201817/6/2026
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).
ModificadaCrítica (9.8)8.5%💥 ExploitWatchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 Firmware30/4/201817/6/2026
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.
ModificadaAlta (8.8)4.2%💥 ExploitWatchguard Hawkeye G23/10/201717/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/json; turn off the (2) Url matching, (3) DNS Inject, or (4) IP…
ModificadaAlta (7.5)1.6%—Watchguard Fireware20/9/201717/6/2026
An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI. By continuously executing the failed login attempts, UI management…
ModificadaMedia (6.1)0.95%—Watchguard Fireware20/9/201717/6/2026
An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the user element, the code will be rendered in the context of any logged…
ModificadaMedia (5.9)0.66%—Watchguard Panda Mobile Security5/5/201717/6/2026
Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
Orbitaley — Vulnerabilidades