Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Sonicwall SMA 100 FirmwareSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 Firmware+2 | 23/12/2021 | 17/6/2026 | A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions. | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.8) | 0.88% | — | Sonicwall Global VPN Client | 8/12/2021 | 17/6/2026 | SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system. | |
| Modificada | Crítica (9.8) | 25% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | |
| Modificada | Alta (8.8) | 40% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | |
| Modificada | Alta (8.8) | 23% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | |
| Modificada | Crítica (9.8) | 3.7% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | |
| Modificada | Alta (7.5) | 21% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | |
| Modificada | Alta (7.5) | 25% | — | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | |
| Modificada | Alta (8.8) | 79% | 💥 Exploit | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 400 Firmware+1 | 8/12/2021 | 17/6/2026 | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv,… | |
| Modificada | Media (6.1) | 13% | 💥 Exploit | Sonicwall Sonicos | 12/10/2021 | 17/6/2026 | A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains. | |
| Modificada | Media (6.5) | 0.64% | — | Dell Enterprise Sonic OS | 1/10/2021 | 17/6/2026 | Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks. | |
| Analizada | Media (6.5) | 4.2% | ⚠ Explotación activa | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+1 | 27/9/2021 | 17/6/2026 | Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS. | |
| Modificada | Crítica (9.1) | 81% | 💥 Exploit | Sonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+1 | 27/9/2021 | 17/6/2026 | An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. | |
| Modificada | Alta (7.8) | 0.42% | — | Sonicwall Global VPN Client | 21/9/2021 | 17/6/2026 | SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host operating system. This vulnerability impacts GVC 4.10.5 installer and earlier. | |
| Modificada | Crítica (9.8) | 2.0% | — | Sonicwall Analytics | 10/8/2021 | 17/6/2026 | SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potentially leads to Remote Code Execution. This vulnerability impacts Analytics On-Prem 2.5.2518 and earlier. | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa | Sonicwall SMA 210 FirmwareSonicwall SMA 410 FirmwareSonicwall SMA 500v FirmwareSonicwall SRA 4600 Firmware+2 | 4/8/2021 | 17/6/2026 | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier | |
| Modificada | Alta (7.8) | 9.7% | 💥 PoC | Linux KernelFedoraproject FedoraDebian LinuxNetapp HCI Management Node+3 | 20/7/2021 | 17/6/2026 | fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05. | |
| Modificada | Alta (8.1) | 0.64% | — | Sonicwall Switch | 9/7/2021 | 17/6/2026 | Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system instability or potentially read sensitive information from the memory locations. | |
| Modificada | Media (5.5) | 0.69% | — | Panasonic Fpwin PRO | 9/7/2021 | 17/6/2026 | Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that is accessible in the context of the user executing software. | |
| Modificada | Alta (7.5) | 1.4% | — | Sonicwall SonicosSonicwall Sonicosv | 23/6/2021 | 17/6/2026 | A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Sonicwall Sonicos | 14/6/2021 | 17/6/2026 | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls. |