Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.94% | — | Watchguard FireboxAI | 9/9/2026 | 9/9/2026 | The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to… | |
| Aplazada | Media (5.3) | 0.33% | — | Firebox PopupsAI | 18/6/2026 | 18/6/2026 | The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via the 'form_id' parameter. This makes it possible for unauthenticated attackers to extract download a full CSV export of all form submissions —… | |
| Aplazada | Media (6.5) | 0.19% | — | Watchguard FireboxAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FirePlugins FireBox firebox allows Stored XSS.This issue affects FireBox: from n/a through <= 3.1.0-free. | |
| Aplazada | Alta (8.9) | 0.32% | — | Watchguard FireboxAI | 24/10/2025 | 8/8/2026 | An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command. | |
| Aplazada | Media (4.8) | 0.48% | — | Watchguard FireboxAI | 15/9/2025 | 8/8/2026 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface… | |
| Aplazada | Media (4.8) | 0.54% | — | Watchguard FireboxAI | 16/5/2025 | 8/8/2026 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management… | |
| Aplazada | Media (4.8) | 0.55% | — | Watchguard FireboxAI | 14/2/2025 | 8/8/2026 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of… | |
| Aplazada | Media (6.5) | 1.3% | — | Watchguard Fireware OSAIWatchguard FireboxAIWatchguard XTMAI | 28/1/2025 | 17/6/2026 | An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances | |
| Modificada | Media (5) | 1.7% | — | Watchguard Firebox Pptp VPN | 7/4/2008 | 16/6/2026 | The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Alta (10) | 4.3% | — | RapidstreamWatchguard Firebox | 2/4/2003 | 16/6/2026 | Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the password parameter. | |
| Modificada | Alta (10) | 2.8% | — | RapidstreamWatchguard Firebox | 2/4/2003 | 16/6/2026 | The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privileges. | |
| Modificada | Media (5) | 1.7% | — | Watchguard FireboxWatchguard Soho Firewall | 4/10/2002 | 16/6/2026 | Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to TCP port 4110. | |
| Modificada | Alta (7.5) | 1.8% | — | Watchguard Firebox 2500Watchguard Firebox 4500 | 20/9/2001 | 16/6/2026 | SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes. | |
| Modificada | Media (5) | 1.3% | — | Watchguard Firebox II | 2/8/2001 | 16/6/2026 | Watchguard Firebox II prior to 4.6 allows a remote attacker to create a denial of service in the kernel via a large stream (>10,000) of malformed ICMP or TCP packets. | |
| Modificada | Media (5) | 1.7% | — | Watchguard Firebox II | 2/6/2001 | 16/6/2026 | Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets. | |
| Modificada | Alta (10) | 2.3% | — | Watchguard Firebox II | 26/3/2001 | 16/6/2026 | Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication. | |
| Modificada | Media (5) | 1.8% | — | Watchguard Firebox II | 9/1/2001 | 16/6/2026 | WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling. | |
| Modificada | Media (5) | 1.8% | — | Watchguard Firebox | 20/10/2000 | 16/6/2026 | Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100. |