Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
183 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Watchguard Fireware | 6/9/2022 | 17/6/2026 | An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4. | |
| Modificada | Alta (7.5) | 2.0% | — | Watchguard Fireware | 6/9/2022 | 17/6/2026 | WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4. | |
| Modificada | Crítica (9.1) | 1.3% | — | Watchguard Fireware | 7/6/2022 | 17/6/2026 | WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | |
| Analizada | Crítica (9.8) | 78% | ⚠ Explotación activa💥 Exploit | Watchguard Fireware | 4/3/2022 | 17/6/2026 | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | |
| Modificada | Media (6.5) | 0.90% | — | Watchguard Fireware | 24/2/2022 | 17/6/2026 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to modify privileged management user credentials. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | |
| Modificada | Alta (8.8) | 1.3% | — | Watchguard Fireware | 24/2/2022 | 17/6/2026 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | |
| Modificada | Alta (8.8) | 2.1% | — | Watchguard Fireware | 24/2/2022 | 17/6/2026 | A systemd stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through… | |
| Modificada | Alta (8.8) | 2.1% | — | Watchguard Fireware | 24/2/2022 | 17/6/2026 | A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through… | |
| Modificada | Alta (8.8) | 1.8% | — | Watchguard Fireware | 24/2/2022 | 17/6/2026 | An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before… | |
| Modificada | Media (6.5) | 0.70% | — | Watchguard Fireware | 24/2/2022 | 17/6/2026 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve certificate private keys. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa | Watchguard Fireware | 24/2/2022 | 17/6/2026 | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3. | |
| Modificada | Alta (7.8) | 0.37% | — | Watchguard Panda Antivirus | 13/1/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the use of named… | |
| Modificada | Crítica (9.8) | 74% | — | Nagios XI Watchguard Wizard | 13/8/2021 | 17/6/2026 | Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection). | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Watchguard AD Helper Firmware | 12/3/2020 | 17/6/2026 | The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI. | |
| Modificada | Media (6.1) | 1.2% | — | Watchguard Fireware XTM | 7/2/2020 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script. | |
| Modificada | Media (6.1) | 0.77% | — | Watchguard Xmt515 Firmware | 7/1/2020 | 17/6/2026 | A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to execute JavaScript in the victim's browser by tricking the victim into clicking on a crafted link. The payload was tested in Microsoft Internet Explorer 11.418.18362.0 and Microsoft Edge… | |
| Modificada | Media (6.1) | 0.94% | — | Watchguard Fireware | 23/8/2019 | 17/6/2026 | The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect). | |
| Modificada | Crítica (9.8) | 1.3% | — | Watchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 FirmwareWatchguard Ap300 Firmware | 2/5/2018 | 17/6/2026 | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. Incorrect validation of the "old password" field in the change password form allows an attacker to bypass validation of this field. | |
| Modificada | Alta (8.8) | 6.5% | 💥 Exploit | Watchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 FirmwareWatchguard Ap300 Firmware | 2/5/2018 | 17/6/2026 | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as… | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Watchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 Firmware | 30/4/2018 | 17/6/2026 | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user). | |
| Modificada | Crítica (9.8) | 8.5% | 💥 Exploit | Watchguard Ap200 FirmwareWatchguard Ap102 FirmwareWatchguard Ap100 Firmware | 30/4/2018 | 17/6/2026 | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false. | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Watchguard Hawkeye G | 23/10/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/json; turn off the (2) Url matching, (3) DNS Inject, or (4) IP… | |
| Modificada | Alta (7.5) | 1.6% | — | Watchguard Fireware | 20/9/2017 | 17/6/2026 | An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI. By continuously executing the failed login attempts, UI management… | |
| Modificada | Media (6.1) | 0.95% | — | Watchguard Fireware | 20/9/2017 | 17/6/2026 | An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the user element, the code will be rendered in the context of any logged… | |
| Modificada | Media (5.9) | 0.66% | — | Watchguard Panda Mobile Security | 5/5/2017 | 17/6/2026 | Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call. |