Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.87% | — | Sonicwall Global Management System | 13/10/2022 | 17/6/2026 | SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files. | |
| Modificada | Alta (7.5) | 0.91% | — | Dell Enterprise Sonic Distribution | 10/10/2022 | 17/6/2026 | Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication. | |
| Modificada | Crítica (9.1) | 1.3% | — | Sonicjs | 1/10/2022 | 17/6/2026 | SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete. | |
| Modificada | Alta (8.8) | 6.7% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+1 | 26/8/2022 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and earlier versions. | |
| Analizada | Alta (7.5) | 0.62% | — | Sonicwall Hosted Email Security | 29/7/2022 | 17/6/2026 | Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions | |
| Modificada | Crítica (9.8) | 9.5% | — | Sonicwall AnalyticsSonicwall Global Management System | 29/7/2022 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions. | |
| Modificada | Alta (8.8) | 6.2% | — | Sonicwall Sws12-10fpoe FirmwareSonicwall Sws12-8 FirmwareSonicwall Sws12-8poe FirmwareSonicwall Sws14-24 Firmware+3 | 29/7/2022 | 17/6/2026 | Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host system. This vulnerability impacts SonicWall Switch 1.1.1.0-2s and earlier versions | |
| Modificada | Alta (8.8) | 13% | — | Sonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 500v Firmware | 8/6/2022 | 17/6/2026 | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack. | |
| Modificada | Crítica (9.8) | 1.2% | — | Allgeier Metasonic DOC Webclient | 16/5/2022 | 17/6/2026 | Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist. | |
| Modificada | Crítica (9.8) | 7.8% | — | Sonicwall SMA 6200 FirmwareSonicwall SMA 6210 FirmwareSonicwall SMA 7200 FirmwareSonicwall SMA 7210 Firmware+1 | 13/5/2022 | 17/6/2026 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability. | |
| Modificada | Alta (7.8) | 0.51% | — | Sonicwall Netextender | 13/5/2022 | 17/6/2026 | A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system. | |
| Modificada | Media (6.1) | 9.1% | — | Sonicwall SMA 6200 FirmwareSonicwall SMA 6210 FirmwareSonicwall SMA 7200 FirmwareSonicwall SMA 7210 Firmware+1 | 13/5/2022 | 17/6/2026 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability. | |
| Modificada | Alta (7.5) | 4.8% | — | Sonicwall SMA 6200 FirmwareSonicwall SMA 6210 FirmwareSonicwall SMA 7200 FirmwareSonicwall SMA 7210 Firmware+1 | 13/5/2022 | 17/6/2026 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data. | |
| Modificada | Alta (7.8) | 0.74% | — | Sonicwall Global VPN Client | 4/5/2022 | 17/6/2026 | SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system. | |
| Modificada | Alta (7.5) | 0.96% | — | Sonicwall Tz300p FirmwareSonicwall Tz300w FirmwareSonicwall Tz350 FirmwareSonicwall Tz350w Firmware+45 | 27/4/2022 | 17/6/2026 | A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack | |
| Modificada | Media (5.3) | 0.79% | — | Sonicwall Tz300p FirmwareSonicwall Tz300w FirmwareSonicwall Tz350 FirmwareSonicwall Tz350w Firmware+45 | 27/4/2022 | 17/6/2026 | A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext. | |
| Modificada | Media (5.3) | 0.79% | — | Sonicwall Tz300p FirmwareSonicwall Tz300w FirmwareSonicwall Tz350 FirmwareSonicwall Tz350w Firmware+45 | 27/4/2022 | 17/6/2026 | A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user. | |
| Modificada | Alta (7.5) | 1.1% | — | Sonicwall Sonicos | 27/4/2022 | 17/6/2026 | Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable. | |
| Modificada | Media (4.9) | 1.1% | — | Sonicwall SRA 1200 FirmwareSonicwall SRA 4200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 Firmware+1 | 13/4/2022 | 17/6/2026 | A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series… | |
| Modificada | Crítica (9.8) | 76% | 💥 PoC | Sonicwall SonicosSonicwall Sonicosv | 25/3/2022 | 17/6/2026 | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall. | |
| Modificada | Crítica (9.8) | 1.9% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+5 | 17/3/2022 | 17/6/2026 | Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and… | |
| Analizada | Alta (7.8) | 93% | ⚠ Explotación activa💥 Exploit | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+25 | 10/3/2022 | 17/6/2026 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read… | |
| Modificada | Alta (8.8) | 1.9% | — | Sonicwall Sonicos | 10/1/2022 | 17/6/2026 | A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions. | |
| Modificada | Alta (8.8) | 1.9% | — | Sonicwall Sonicos | 10/1/2022 | 17/6/2026 | A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions. | |
| Modificada | Alta (7.5) | 0.90% | — | Sonicwall SMA 100 FirmwareSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 Firmware+2 | 23/12/2021 | 17/6/2026 | An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data. |