Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2834▲ 197 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1724 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.8% | 💥 Exploit | Checkpoint Firewall-1 | 18/7/2001 | 16/6/2026 | The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication. | |
| Modificada | Alta (7.5) | 2.0% | — | Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+4 | 18/7/2001 | 16/6/2026 | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. | |
| Modificada | Media (5) | 4.1% | — | Mandrakesoft Mandrake Single Network FirewallOpenldapDebian LinuxMandrakesoft Mandrake Linux+2 | 16/7/2001 | 16/6/2026 | slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field. | |
| Modificada | Alta (7.5) | 2.8% | — | Checkpoint Firewall-1Checkpoint Provider-1Checkpoint Vpn-1 | 12/7/2001 | 16/6/2026 | Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection. | |
| Modificada | Alta (7.5) | 3.2% | — | Checkpoint Firewall-1 | 9/7/2001 | 16/6/2026 | Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Cisco PIX Firewall 515Cisco PIX Firewall 520 | 18/6/2001 | 16/6/2026 | Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests. | |
| Modificada | Alta (7.5) | 1.9% | — | Symantec Raptor Firewall | 18/6/2001 | 16/6/2026 | Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set. | |
| Modificada | Alta (7.5) | 1.9% | — | Nokia Ip440 Firewall VPN Appliance | 2/6/2001 | 16/6/2026 | Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL. | |
| Modificada | Media (5) | 1.8% | — | Borderware Firewall Server | 2/6/2001 | 16/6/2026 | Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network. | |
| Modificada | Media (5) | 1.6% | — | Checkpoint Firewall-1 | 26/3/2001 | 16/6/2026 | FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Watchguard Soho Firewall | 16/2/2001 | 16/6/2026 | WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests. | |
| Modificada | Alta (10) | 6.2% | — | Watchguard Soho Firewall | 12/2/2001 | 16/6/2026 | Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request. | |
| Modificada | Media (5) | 1.8% | — | Watchguard Soho Firewall | 12/2/2001 | 16/6/2026 | WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Checkpoint Firewall-1 | 12/2/2001 | 16/6/2026 | Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets. | |
| Modificada | Alta (10) | 1.9% | — | Watchguard Soho Firewall | 12/2/2001 | 16/6/2026 | HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities. | |
| Modificada | Media (5) | 1.3% | — | Sonicwall Soho Firewall | 9/1/2001 | 16/6/2026 | The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request. | |
| Modificada | Media (5) | 1.8% | — | Sonicwall Soho Firewall | 9/1/2001 | 16/6/2026 | The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page. | |
| Modificada | Alta (7.2) | 0.40% | — | TIS Internet Firewall Toolkit | 19/12/2000 | 23/9/2026 | Vulnerabilidad de formato de cadena en x-gw en TIS Firewall Toolkit (FWTK) permite a usuarios locales ejecutar comandos arbitrarios mediante un nombre de visualización malformado. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Checkpoint Firewall-1 | 11/12/2000 | 16/6/2026 | Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack. | |
| Modificada | Media (5) | 1.8% | — | Checkpoint Firewall-1 | 11/12/2000 | 16/6/2026 | The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall. | |
| Modificada | Media (5) | 1.7% | — | IBM As400 Firewall | 11/12/2000 | 16/6/2026 | The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request. | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Cisco PIX Firewall Software | 11/12/2000 | 16/6/2026 | The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Cisco PIX Firewall Software | 11/12/2000 | 23/9/2026 | Cisco Secure PIX Firewall 5.2(2) permite a atacantes remotos determinar la dirección IP real de un servidor FTP objetivo inundando el servidor con solicitudes PASV, lo que incluye la dirección IP real en la respuesta cuando se establece el modo pasivo. | |
| Modificada | Media (5) | 2.1% | — | Checkpoint Firewall-1 | 14/11/2000 | 16/6/2026 | The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka "Inter-module Communications Bypass." | |
| Modificada | Alta (7.5) | 1.4% | — | Checkpoint Firewall-1 | 14/11/2000 | 16/6/2026 | Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka "Retransmission of Encapsulated Packets." |