Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
972 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.59% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input. | |
| Analizada | Crítica (9.2) | 0.94% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with… | |
| Analizada | Alta (8.7) | 0.61% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured… | |
| Modificada | Alta (7.3) | 0.14% | — | Watchguard Mobile VPN With SSLWatchguard Fireware | 3/7/2026 | 10/8/2026 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2. | |
| Modificada | Alta (8.6) | 0.60% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. | |
| Modificada | Alta (8.6) | 0.64% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. | |
| Analizada | Alta (8.6) | 0.64% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI. | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"php jobs/text_to_subtitles.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAIPHPAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php jobs/transcribe.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(\"php jobs/transcribe_amazon.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php jobs/translate_text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php jobs/speech_audio_text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without sanitization: exec(\"php jobs/speech_audio_mac.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language SystemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"php jobs/speech_audio_mac_text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAIPHPAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php jobs/complex.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/speech_audio.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters… | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. | |
| Aplazada | Alta (8.7) | 0.46% | — | Guardian Language-systemAI | 1/7/2026 | 24/8/2026 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents. |